Loading market data...
← Back to CVE feed

CVE-2026-85572

UNKNOWN View on NVD ↗

Description

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation.

Published: Sep 16, 2026 06:16 UTC Modified: Sep 16, 2026 20:25 UTC