CVE-2026-14310

Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.


We have discovered 8,861 live websites that are affected by CVE-2026-14310.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains8,861 live websites (100% of Tutor LMS install base)
Vulnerable Versions
  • from 0 through 4
Vulnerable Versions Count127 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Sanjar Tulkinov (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14310
United States2,529 websites



Germany680 websites
Poland438 websites
Cyprus437 websites
France435 websites
India403 websites
GB393 websites
Brazil327 websites
Spain258 websites
Italy238 websites

Website Distribution by TLD

Number of websites using CVE-2026-14310
.com4,113 websites
.org596 websites
.pl347 websites
.com.br289 websites
.de208 websites
.net180 websites
.it167 websites
.fr153 websites
.co.uk146 websites
.nl121 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14310

Top websites that are affected by CVE-2026-14310. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States**,***
**********.com United States**,***
*****************.com GB**,***
***************.org United States**,***
*************.org United States**,***
**********.com GB**,***
********************.com United States***,***
*****.com France***,***
**************.com Spain***,***
************.org United States***,***
See full domain list

FAQ

CVE-2026-14310 is Authorization Bypass Through User-Controlled Key in Tutor LMS
A total of 8,861 websites have been identified as vulnerable to CVE-2026-14310, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2026-14310 vulnerability.
Tutor LMS versions up to 4 are vulnerable to CVE-2026-14310.
CVE-2026-14310 is resolved in version 4 of Tutor LMS.