
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13935 is a Missing Authorization vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress, allowing authenticated attackers to fraudulently mark any course as completed. It affects all versions of the plugin up to and including 3.9.2. The vulnerability was disclosed on January 9, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, NVD).
The root cause is classified as CWE-862 (Missing Authorization). Specifically, the mark_course_complete function in classes/Course.php fails to verify whether the requesting user is actually enrolled in the target course before updating its completion status. Any authenticated user with subscriber-level access or higher can send a crafted request to this function, specifying an arbitrary course ID, and the system will record that course as completed without validating enrollment. The fix was applied in the plugin's changeset 3422766, modifying Course.php to add the missing enrollment check (Wordfence, Plugin Changeset).
Successful exploitation allows authenticated attackers to falsify course completion records for any course on the platform, regardless of actual participation or enrollment. This undermines the integrity of the LMS platform's credentialing system, enabling fraudulent certification claims and potentially allowing users to bypass paid course requirements. There is no confidentiality or availability impact; the damage is limited to data integrity within the course management system (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid WordPress account with subscriber-level access or above, making it low-complexity but limited in scope to authenticated users (Wordfence).
/wp-content/plugins/tutor/readme.txt.wp-admin/admin-ajax.php) invoking the mark_course_complete action with the target course ID as a parameter, without being enrolled in that course.wp-admin/admin-ajax.php with the mark_course_complete action from accounts not enrolled in the referenced course IDs.wp_tutor_course_completed) for users with no corresponding enrollment records in the enrollment table.Site administrators should update the Tutor LMS plugin to version 3.9.3 or later, which includes the fix applied in changeset 3422766 that adds enrollment verification to the mark_course_complete function. If an immediate update is not possible, restricting new user registrations or limiting subscriber-level account creation can reduce exposure. Administrators should also audit existing course completion records for anomalies indicating prior exploitation (Plugin Changeset, Wordfence).
The vulnerability was reported by Wordfence and received standard coverage from vulnerability aggregation platforms. No notable vendor statements beyond the patch release or significant researcher commentary have been identified. Community reaction has been minimal, consistent with the Medium severity rating and limited exploitation potential.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."