nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13935 CVE-2025-13935
MEDIUM
Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion
Record summary
CVE-2025-13935 has a selected CVSS score of 4.3 (medium).
Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subscriber level access and above, to mark any course as completed.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Tutor LMS – eLearning and online course solutionBrowse themeum / Tutor LMS – eLearning and online course solutionDefault status: unaffected | CVE List | Through 3.9.2 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3422766/tutor/trunk/classes/Course.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/7b8b111a-9626-41f4-8a13-51f576af0257?source=cve