CVE-2025-13935: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13935 is a Missing Authorization vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress, allowing authenticated attackers to fraudulently mark any course as completed. It affects all versions of the plugin up to and including 3.9.2. The vulnerability was disclosed on January 9, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). Specifically, the mark_course_complete function in classes/Course.php fails to verify whether the requesting user is actually enrolled in the target course before updating its completion status. Any authenticated user with subscriber-level access or higher can send a crafted request to this function, specifying an arbitrary course ID, and the system will record that course as completed without validating enrollment. The fix was applied in the plugin's changeset 3422766, modifying Course.php to add the missing enrollment check (Wordfence, Plugin Changeset).

Impact

Successful exploitation allows authenticated attackers to falsify course completion records for any course on the platform, regardless of actual participation or enrollment. This undermines the integrity of the LMS platform's credentialing system, enabling fraudulent certification claims and potentially allowing users to bypass paid course requirements. There is no confidentiality or availability impact; the damage is limited to data integrity within the course management system (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid WordPress account with subscriber-level access or above, making it low-complexity but limited in scope to authenticated users (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Tutor LMS plugin at version 3.9.2 or earlier. This can be done by checking the plugin's readme.txt or changelog exposed at /wp-content/plugins/tutor/readme.txt.
  2. Obtain Authentication: Register or log in to the target WordPress site with any account at subscriber level or above (e.g., a free student account on the LMS platform).
  3. Identify Target Course: Browse the LMS to find the course ID of any course the attacker wishes to fraudulently complete. Course IDs are typically visible in page URLs or API responses.
  4. Send Malicious Request: Craft and send an authenticated HTTP POST request to the WordPress AJAX endpoint (e.g., wp-admin/admin-ajax.php) invoking the mark_course_complete action with the target course ID as a parameter, without being enrolled in that course.
  5. Verify Completion: Confirm that the course is now marked as completed in the attacker's profile, enabling access to completion certificates or downstream course content (Wordfence, Plugin Changeset).

Indicators of compromise

  • Logs: WordPress access logs showing repeated POST requests to wp-admin/admin-ajax.php with the mark_course_complete action from accounts not enrolled in the referenced course IDs.
  • Database: Unexpected entries in the Tutor LMS course completion tables (e.g., wp_tutor_course_completed) for users with no corresponding enrollment records in the enrollment table.
  • Application Behavior: Users appearing to hold completion certificates or badges for courses they never enrolled in or accessed, flagged during audit of LMS records.

Mitigation and workarounds

Site administrators should update the Tutor LMS plugin to version 3.9.3 or later, which includes the fix applied in changeset 3422766 that adds enrollment verification to the mark_course_complete function. If an immediate update is not possible, restricting new user registrations or limiting subscriber-level account creation can reduce exposure. Administrators should also audit existing course completion records for anomalies indicating prior exploitation (Plugin Changeset, Wordfence).

Community reactions

The vulnerability was reported by Wordfence and received standard coverage from vulnerability aggregation platforms. No notable vendor statements beyond the patch release or significant researcher commentary have been identified. Community reaction has been minimal, consistent with the Medium severity rating and limited exploitation potential.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management