Insecure Direct Object Reference in Tutor LMS Pro Plugin for WordPress
CVE-2025-6639
5.4MEDIUM
What is CVE-2025-6639?
The Tutor LMS Pro is an eLearning plugin for WordPress that suffers from an Insecure Direct Object Reference vulnerability. In versions up to and including 3.8.3, this flaw arises from insufficient validation on a user-controlled key in the tutor_assignment_submit() function. As a result, it allows authenticated attackers with Subscriber-level access or higher to potentially view and modify assignment submissions belonging to other users, posing a significant risk to student data privacy and integrity.
Affected Version(s)
Tutor LMS Pro * <= 3.8.3