PT-2025-43711 · WordPress · Tutor Lms Pro
Published
2025-10-25
·
Updated
2025-10-25
·
CVE-2025-6639
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tutor LMS Pro versions prior to 3.8.4
Description
The Tutor LMS Pro plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. This is due to a lack of proper validation on a user-controlled key when handling assignment viewing and editing through the
tutor assignment submit() function. Authenticated attackers with Subscriber-level access or higher can potentially view and modify assignment submissions belonging to other students.Recommendations
Update Tutor LMS Pro to version 3.8.4 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms Pro