The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.
We have discovered 8,861 live websites that are affected by CVE-2026-14310.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 8,861 live websites (100% of Tutor LMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 127 versions ( 100% of all versions) |
| 2,529 websites | |
| 680 websites | |
| 438 websites | |
| 437 websites | |
| 435 websites | |
| 403 websites | |
| 393 websites | |
| 327 websites | |
| 258 websites | |
| 238 websites |
| .com | 4,113 websites |
| .org | 596 websites |
| .pl | 347 websites |
| .com.br | 289 websites |
| .de | 208 websites |
| .net | 180 websites |
| .it | 167 websites |
| .fr | 153 websites |
| .co.uk | 146 websites |
| .nl | 121 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.org | **,*** | ||
| **********.com | **,*** | ||
| *****************.com | **,*** | ||
| ***************.org | **,*** | ||
| *************.org | **,*** | ||
| **********.com | **,*** | ||
| ********************.com | ***,*** | ||
| *****.com | ***,*** | ||
| **************.com | ***,*** | ||
| ************.org | ***,*** |
FAQ