CVE-2026-85572: Unknown Tutor Lms

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation.

Affected products

  • Unknown Tutor Lms: from 4.0.0, before 4.0.8 (fixed in 4.0.8)

Published 2026-09-16. Last modified 2026-09-17.