Sensitive Information Exposure in Tutor LMS Plugin for WordPress
CVE-2025-6680

4.3MEDIUM

What is CVE-2025-6680?

The Tutor LMS plugin for WordPress is affected by a vulnerability that allows authenticated users with tutor-level access and above to access assignments from courses they do not teach. This exposure of potentially sensitive information creates a risk of unauthorized information retrieval, highlighting the need for prompt updates to version 3.8.3 or later to safeguard user data effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Tutor LMS – eLearning and online course solution * <= 3.8.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergio Framiñánn García
.