nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13679 CVE-2025-13679
MEDIUM
Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details
Record summary
CVE-2025-13679 has a selected CVSS score of 6.5 (medium).
Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate order IDs and exfiltrate sensitive data (PII), such as student name, email address, phone number, and billing address.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Tutor LMS – eLearning and online course solutionBrowse themeum / Tutor LMS – eLearning and online course solutionDefault status: unaffected | CVE List | Through 3.9.3 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3422766/tutor/tags/3.9.4/ecommerce/OrderController.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/0830d0c3-99c0-423e-99ab-f0c1cbec52d9?source=cve