CVE-2025-13673: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13673 is an unauthenticated SQL Injection vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress, affecting all versions up to and including 3.9.6. The flaw exists in the coupon_code parameter due to insufficient escaping of user-supplied input and lack of proper SQL query preparation. Partial mitigations were introduced in versions 3.9.4 and 3.9.6, but the vulnerability was not fully resolved until a later patch. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability resides in the coupon_code parameter, where user-supplied input is not properly escaped or parameterized before being incorporated into SQL queries. This allows unauthenticated attackers to append additional SQL statements to existing queries — a classic SQL injection pattern — without requiring any authentication, user interaction, or elevated privileges. A public proof-of-concept exploit has been published on GitHub (GitHub PoC, Wordfence).

Impact

Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials (hashed passwords), email addresses, personal data, and potentially secret keys or API tokens stored in the database. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. On sites with a large user base or sensitive course/payment data, the exposure risk is significant and could facilitate account takeover or further attacks (Wordfence, Sucuri Blog).

Exploitability

A public proof-of-concept exploit has been published on GitHub by researcher 'dinosn' (GitHub PoC), and the vulnerability has been indexed by Qualys (detection ID 531040) (Qualys). The EPSS score is approximately 0.064%, indicating a currently low but non-negligible probability of exploitation in the wild. No specific threat actor attribution or CISA KEV catalog listing has been identified at this time. The zero-authentication requirement and wide deployment of the Tutor LMS plugin make this an attractive target for opportunistic attackers.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Tutor LMS plugin (versions ≤ 3.9.6) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:/wp-content/plugins/tutor/).
  2. Locate the vulnerable endpoint: Identify the coupon validation endpoint that processes the coupon_code parameter — typically a REST API or AJAX handler within the Tutor LMS plugin.
  3. Craft the SQL injection payload: Construct a malicious value for the coupon_code parameter that appends additional SQL logic, such as a UNION-based or boolean-based blind injection payload (e.g., ' UNION SELECT user_login,user_pass,NULL FROM wp_users-- -).
  4. Send the unauthenticated request: Submit the crafted HTTP request (GET or POST) to the vulnerable endpoint without any authentication headers or cookies.
  5. Extract data: Parse the HTTP response or use time-based/error-based techniques to enumerate and extract database contents, including WordPress user credentials, email addresses, and other sensitive data (GitHub PoC, Wordfence).

Indicators of compromise

  • Network: Unusual HTTP requests to Tutor LMS coupon-related endpoints (e.g., containing coupon_code parameter) with SQL metacharacters such as single quotes ('), UNION, SELECT, --, or encoded equivalents in the parameter value.
  • Logs: WordPress access logs showing repeated or anomalous requests to coupon validation endpoints from a single IP or user agent; error log entries related to SQL query failures or unexpected database errors.
  • Process/Application: Unexpected database query patterns visible in slow query logs, particularly UNION SELECT statements or queries returning data from wp_users or other sensitive tables.
  • File System: Presence of automated scanning tool artifacts or web shells if the attacker escalated beyond data extraction (not directly caused by this vulnerability but may follow credential theft).

Mitigation and workarounds

Users should update the Tutor LMS plugin to a version beyond 3.9.6 that fully addresses the vulnerability — versions 3.9.4 and 3.9.6 only partially mitigated the issue. The official patch is tracked in the WordPress plugin repository changeset (Plugin Changeset). As an interim measure, site administrators can disable coupon functionality if not in use, or implement a web application firewall (WAF) rule to block SQL injection patterns in the coupon_code parameter. Regularly auditing WordPress plugin versions and enabling automatic updates for security releases is strongly recommended (Wordfence, Sucuri Blog).

Community reactions

The vulnerability was assigned and disclosed by Wordfence, which serves as the primary authoritative source. Sucuri included it in their March 2026 vulnerability patch roundup, noting its significance for WordPress site operators (Sucuri Blog). Social media activity on Mastodon and Bluesky noted the public PoC release, and the vulnerability was picked up by multiple threat intelligence aggregators shortly after disclosure (Qualys).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management