Understanding the Tutor LMS Vulnerability
The Tutor LMS plugin, a popular solution for creating and managing online courses within WordPress, has been identified with a security vulnerability. This flaw could allow unauthorized individuals to bypass critical payment verification processes, potentially marking unpaid orders as successfully paid. This issue stems from a missing security check in the plugin’s code, specifically when it handles webhook requests.
CVE Details
Product: Tutor LMS – eLearning and online course solution plugin for WordPress
Published: October 25, 2025
Severity: Medium
Status: Analyzed
Affected Products
This vulnerability affects all versions of the Tutor LMS – eLearning and online course solution plugin for WordPress up to, and including, version 3.8.3. If you are using any of these versions, your website may be at risk.
Current Status
The vulnerability has been thoroughly analyzed and documented, indicating a clear understanding of its nature and potential impact.
Severity Level
With a CVSS score of 5.3, this vulnerability is rated as Medium Severity. A medium severity rating means that while the issue is significant and can lead to unauthorized actions like payment bypasses, it might require specific conditions or a certain level of attacker sophistication to exploit successfully. Nevertheless, it’s crucial to address such vulnerabilities promptly to maintain the integrity of your eLearning platform and protect your financial transactions.
Possible Solutions
The most effective solution for this type of vulnerability is to update your Tutor LMS plugin to the latest available version. Since the vulnerability affects versions up to and including 3.8.3, it is highly recommended to update to a version released after 3.8.3 as soon as it becomes available. Always ensure your WordPress core, themes, and all other plugins are also kept up-to-date to maintain a robust security posture.
References
https://plugins.trac.wordpress.org/browser/tutor/tags/3.8.3/ecommerce/PaymentGateways/Paypal/src/Payments/Paypal/Paypal.php#L323
https://www.wordfence.com/threat-intel/vulnerabilities/id/26289a93-063b-469a-9d09-c286d76fce0c?source=cve


