CVE-2025-47555: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-47555 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Themeum Tutor LMS WordPress plugin. It affects all versions through 3.9.4 and was reported by researcher Supakiad S. (m3ez) on December 3, 2025, with public disclosure on January 22, 2026. The vulnerability is classified under CWE-639 and carries a CVSS 3.1 base score of 3.8 (Low) as assessed by Patchstack, requiring high privileges (Tutor Instructor role) to exploit (Patchstack).

Technical details

The root cause is an incorrectly configured access control mechanism (CWE-639) that allows user-controlled keys or object identifiers to bypass authorization checks within the Tutor LMS plugin. An authenticated attacker with at least Tutor Instructor-level privileges can manipulate object references in requests to access or modify resources belonging to other users or roles. This is classified as an OWASP Top 10 A1: Broken Access Control issue, and the attack requires no user interaction and is conducted over the network (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with Tutor Instructor privileges to bypass authorization controls, potentially reading sensitive data (confidentiality impact) and modifying information (integrity impact) they are not authorized to access. There is no availability impact. The scope is limited to the affected WordPress installation, but exposure of course data, student records, or other LMS content is plausible depending on the specific object references accessible (Patchstack).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability requires an authenticated session with at least Tutor Instructor-level privileges, which limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Mitigation and workarounds

Themeum has released version 3.9.5 of the Tutor LMS plugin, which patches this vulnerability. Site administrators should update to version 3.9.5 or later immediately. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. As a temporary measure if upgrading is not immediately possible, restrict Tutor Instructor role assignments to trusted users only and monitor for unusual access patterns (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management