
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13673 is an unauthenticated SQL Injection vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress, affecting all versions up to and including 3.9.6. The flaw exists in the coupon_code parameter due to insufficient escaping of user-supplied input and lack of proper SQL query preparation. Partial mitigations were introduced in versions 3.9.4 and 3.9.6, but the vulnerability was not fully resolved until a later patch. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability resides in the coupon_code parameter, where user-supplied input is not properly escaped or parameterized before being incorporated into SQL queries. This allows unauthenticated attackers to append additional SQL statements to existing queries — a classic SQL injection pattern — without requiring any authentication, user interaction, or elevated privileges. A public proof-of-concept exploit has been published on GitHub (GitHub PoC, Wordfence).
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials (hashed passwords), email addresses, personal data, and potentially secret keys or API tokens stored in the database. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. On sites with a large user base or sensitive course/payment data, the exposure risk is significant and could facilitate account takeover or further attacks (Wordfence, Sucuri Blog).
A public proof-of-concept exploit has been published on GitHub by researcher 'dinosn' (GitHub PoC), and the vulnerability has been indexed by Qualys (detection ID 531040) (Qualys). The EPSS score is approximately 0.064%, indicating a currently low but non-negligible probability of exploitation in the wild. No specific threat actor attribution or CISA KEV catalog listing has been identified at this time. The zero-authentication requirement and wide deployment of the Tutor LMS plugin make this an attractive target for opportunistic attackers.
inurl:/wp-content/plugins/tutor/).coupon_code parameter — typically a REST API or AJAX handler within the Tutor LMS plugin.coupon_code parameter that appends additional SQL logic, such as a UNION-based or boolean-based blind injection payload (e.g., ' UNION SELECT user_login,user_pass,NULL FROM wp_users-- -).coupon_code parameter) with SQL metacharacters such as single quotes ('), UNION, SELECT, --, or encoded equivalents in the parameter value.wp_users or other sensitive tables.Users should update the Tutor LMS plugin to a version beyond 3.9.6 that fully addresses the vulnerability — versions 3.9.4 and 3.9.6 only partially mitigated the issue. The official patch is tracked in the WordPress plugin repository changeset (Plugin Changeset). As an interim measure, site administrators can disable coupon functionality if not in use, or implement a web application firewall (WAF) rule to block SQL injection patterns in the coupon_code parameter. Regularly auditing WordPress plugin versions and enabling automatic updates for security releases is strongly recommended (Wordfence, Sucuri Blog).
The vulnerability was assigned and disclosed by Wordfence, which serves as the primary authoritative source. Sucuri included it in their March 2026 vulnerability patch roundup, noting its significance for WordPress site operators (Sucuri Blog). Social media activity on Mastodon and Bluesky noted the public PoC release, and the vulnerability was picked up by multiple threat intelligence aggregators shortly after disclosure (Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."