CVE-2025-13679
MEDIUMTutor LMS < 3.9.3 - Authenticated Missing Authorization in get_order_by_id()
Title source: llmDescription
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate order IDs and exfiltrate sensitive data (PII), such as student name, email address, phone number, and billing address.
References (2)
Core 2
Scores
CVSS v3
6.5
EPSS
0.0021
EPSS Percentile
10.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
themeum/Tutor LMS – eLearning and online course solution
< 3.9.3
Published
Jan 08, 2026
Tracked Since
Feb 18, 2026