
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47555 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Themeum Tutor LMS WordPress plugin. It affects all versions through 3.9.4 and was reported by researcher Supakiad S. (m3ez) on December 3, 2025, with public disclosure on January 22, 2026. The vulnerability is classified under CWE-639 and carries a CVSS 3.1 base score of 3.8 (Low) as assessed by Patchstack, requiring high privileges (Tutor Instructor role) to exploit (Patchstack).
The root cause is an incorrectly configured access control mechanism (CWE-639) that allows user-controlled keys or object identifiers to bypass authorization checks within the Tutor LMS plugin. An authenticated attacker with at least Tutor Instructor-level privileges can manipulate object references in requests to access or modify resources belonging to other users or roles. This is classified as an OWASP Top 10 A1: Broken Access Control issue, and the attack requires no user interaction and is conducted over the network (Patchstack).
Successful exploitation allows an authenticated attacker with Tutor Instructor privileges to bypass authorization controls, potentially reading sensitive data (confidentiality impact) and modifying information (integrity impact) they are not authorized to access. There is no availability impact. The scope is limited to the affected WordPress installation, but exposure of course data, student records, or other LMS content is plausible depending on the specific object references accessible (Patchstack).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability requires an authenticated session with at least Tutor Instructor-level privileges, which limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
Themeum has released version 3.9.5 of the Tutor LMS plugin, which patches this vulnerability. Site administrators should update to version 3.9.5 or later immediately. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. As a temporary measure if upgrading is not immediately possible, restrict Tutor Instructor role assignments to trusted users only and monitor for unusual access patterns (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."