---
id: CVE-2026-85572
title: >-
  The Tutor LMS  WordPress plugin before 4.0.8 does not check that a user has
  access to a course before returning its lesson discussion content, allowing
  any authenticated user, such as a subscriber, to read comments from courses
  they are …
summary: >-
  The Tutor LMS  WordPress plugin before 4.0.8 does not check that a user has
  access to a course before returning its lesson discussion content, allowing
  any authenticated user, such as a subscriber, to read comments from courses
  they are …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Tutor LMS
affected:
  - tutor_lms >= 4.0.0 < 4.0.8
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:51.287'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85572'
references:
  - url: 'https://wpscan.com/vulnerability/a02f2c69-69cf-46fa-b4cf-0cf990d71e57/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:18:49.770732Z'
epss: 0.00282
epssPercentile: 0.20931
ingestedAt: '2026-09-16T06:51:06.251Z'
---

## Overview

The Tutor LMS  WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
