Insecure Direct Object Reference in Tutor LMS Pro Plugin for WordPress
CVE-2025-6639

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 October 2025

What is CVE-2025-6639?

The Tutor LMS Pro is an eLearning plugin for WordPress that suffers from an Insecure Direct Object Reference vulnerability. In versions up to and including 3.8.3, this flaw arises from insufficient validation on a user-controlled key in the tutor_assignment_submit() function. As a result, it allows authenticated attackers with Subscriber-level access or higher to potentially view and modify assignment submissions belonging to other users, posing a significant risk to student data privacy and integrity.

Affected Version(s)

Tutor LMS Pro * <= 3.8.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergio Framiñánn García
.