PT-2025-43706 · WordPress · Tutor Lms

·

CVE-2025-11564

·

Publicado

2025-10-25

·

Atualizado

2025-12-05

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS versions up to and including 3.8.3
Description The Tutor LMS plugin for WordPress is susceptible to unauthorized data modification. This occurs because of a missing capability check when verifying webhook signatures within the verifyAndCreateOrderData() function. This allows unauthenticated attackers to circumvent payment verification and falsely mark orders as paid by sending crafted webhook requests with the payment type parameter set to 'recurring'.
Recommendations Update Tutor LMS to a version newer than 3.8.3.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11564

Produtos afetados

Tutor Lms