The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeum
Themeum tutor Lms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themeum
Themeum tutor Lms Wordpress Wordpress wordpress |
Fri, 09 Jan 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow. | |
| Title | Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-09T19:11:47.452Z
Reserved: 2025-12-02T22:22:20.669Z
Link: CVE-2025-13934
Updated: 2026-01-09T19:11:43.645Z
Status : Received
Published: 2026-01-09T08:15:57.007
Modified: 2026-01-09T08:15:57.007
Link: CVE-2025-13934
No data.
OpenCVE Enrichment
Updated: 2026-01-09T13:23:42Z