
🚨*CVE* CVE-2026-14187 The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to re… https://www.cve.org/CVERecord?id=CVE-2026-14187 ----- Traducción: CVE-2026-14187 El … http://infoflow.cloud`
Post summary
The CVE reports an ownership enforcement flaw in Tutor LMS WordPress plugin versions before 4.0.6, allowing instructors to manipulate any course content, but no PoC, exploit code, patch, or evidence of active exploitation is provided.


