Tutor LMS Sensitive Information Exposure Vulnerability (CVE-2025-6680) — Medium Severity

Understanding the Sensitive Information Exposure in Tutor LMS

A notable security vulnerability has been identified in the Tutor LMS – eLearning and online course solution plugin for WordPress. This flaw, tracked as CVE-2025-6680, allows for sensitive information exposure, meaning certain private data could be accessed by unauthorized individuals.

In simple terms, if you use Tutor LMS to run your online courses, there’s a risk that an attacker who is logged into your site with “tutor-level” access or higher could view assignments belonging to courses they aren’t actually teaching. These assignments might contain sensitive details that should remain private, leading to an unauthorized disclosure of information.

CVE Details

  • Product: Tutor LMS – eLearning and online course solution plugin for WordPress
  • Published: October 25, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

This vulnerability impacts all versions of the Tutor LMS free plugin for WordPress up to, and including, version 3.8.3. If you are running any version within this range, your installation could be at risk.

Current Status

The vulnerability has been officially analyzed. The developers of Tutor LMS have addressed this issue in versions released after 3.8.3. This means a fix is available, and users should prioritize updating their systems.

Severity Level

Rated as "Medium" severity, this vulnerability is not immediately exploitable by just anyone. It requires an authenticated attacker (someone already logged into your WordPress site) with at least “tutor-level” privileges. However, once exploited, the attacker could gain access to sensitive information within student assignments, which could have privacy and academic integrity implications.

Possible Solutions

The most crucial step to protect your Tutor LMS installation is to update the plugin immediately to the latest available version. The developers have released a patch that includes a necessary permission check to prevent unauthorized access to assignments. The code changes introduce a check to ensure that only users with the appropriate permissions to edit a specific course can review its assignments.

Specifically, the fix adds a validation to confirm if the current user has the capability to edit the course associated with the assignment before allowing them to view it. This closes the loophole that allowed tutors to see assignments for courses they weren’t authorized to teach.

Always ensure your WordPress core, themes, and all plugins are kept up to date to maintain a strong security posture. For additional security, consider implementing WordPress security best practices on your website.

References

https://plugins.trac.wordpress.org/changeset/3382577/tutor/trunk/templates/dashboard/assignments/review.php?old=3249440&old_path=tutor%2Ftrunk%2Ftemplates%2Fdashboard%2Fassignments%2Freview.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/1b8d88e4-a9dc-4740-b836-99f730beefcb?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.