CVE-2026-85572
Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation.
| Vendor | unknown |
| Product | tutor lms |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown tutor lms
Be the first to know when new unknown vulnerabilities affecting unknown tutor lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Tutor LMS
4.0.0 < 4.0.8
References
Credits
Shirshak WPScan