The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.
https://wpscan.com/vulnerability/fb006829-e298-4b22-9d62-293a3b917ccd/