PT-2026-56415 · Undefined · Undefined

CVE-2026-14306

·

Published

2026-07-08

·

Updated

2026-07-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
I've been busy.
I have two new CVEs disclosed:
CVE-2026-57339: Business Directory Plugin (<= 6.4.23). it allowed unauthenticated deletion of any listing on a website. Then there is CVE-2026-14306: Tutor LMS (< 3.9.14). which was some sort of payment bypass where you could view lessons not paid for.
Write-ups and PoCs are on my github: https://t.co/A2uWeIh1Kz
#infosec #bugbounty #WordPress
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-14306

Affected Products

Undefined