Skip to main content

CVE-2025-6680: Tutor LMS Information Disclosure Vulnerability

CVE-2025-6680 is an information disclosure vulnerability in Themeum Tutor LMS for WordPress that allows tutors to view assignments from courses they don't teach. This article covers the technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-6680 Overview

The Tutor LMS eLearning and online course solution plugin for WordPress contains a sensitive information exposure vulnerability affecting all versions up to and including 3.8.3. Authenticated users with tutor-level access or above can view assignments belonging to courses they do not teach. These assignments may contain sensitive information intended only for authorized instructors. The flaw resides in the assignments review template at templates/dashboard/assignments/review.php and stems from missing authorization checks on assignment access [CWE-284].

Critical Impact

Authenticated tutors can read assignment content from courses outside their teaching scope, exposing potentially sensitive learner data and instructional material.

Affected Products

  • Themeum Tutor LMS (free, WordPress) versions up to and including 3.8.3
  • WordPress sites running the Tutor LMS plugin with tutor-level or higher user accounts
  • Installations exposing the assignment review dashboard to non-course instructors

Discovery Timeline

  • 2025-10-25 - CVE-2025-6680 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6680

Vulnerability Analysis

The vulnerability is a broken access control issue in the Tutor LMS assignment review workflow. The plugin exposes assignment review functionality to any authenticated user holding the tutor role or higher. It does not verify that the requesting user actually teaches the course associated with the requested assignment. As a result, an authenticated tutor can enumerate or directly request assignments belonging to other instructors and read their contents. Because assignments frequently contain learner submissions, grading notes, and instructional context, this exposure can leak personal and academic data across course boundaries.

Root Cause

The root cause is a missing authorization check in templates/dashboard/assignments/review.php. The template loads assignment data based on a supplied identifier without confirming that the current user owns or co-teaches the parent course. Authentication is enforced, but authorization is not, which is the defining pattern of [CWE-284] Improper Access Control. The upstream fix modifies this template to add the missing ownership validation.

Attack Vector

An attacker requires an existing account with the tutor capability on the target WordPress site. Once authenticated, the attacker requests the assignments review endpoint with an assignment identifier belonging to another instructor's course. The plugin returns the assignment data because it never verifies the relationship between the requester and the parent course. No user interaction from the victim is required, and exploitation is achievable over the network with low complexity.

No public proof-of-concept exploit is currently available. Technical details are documented in the Wordfence Vulnerability Report and the WordPress Plugin Code Change.

Detection Methods for CVE-2025-6680

Indicators of Compromise

  • Web server access logs showing tutor-level accounts requesting the assignments review endpoint with identifiers outside their assigned courses
  • Unexpected HTTP GET requests to URLs referencing dashboard/assignments/review from users who do not teach the queried course
  • Sequential or scripted enumeration of assignment identifiers by a single authenticated tutor account

Detection Strategies

  • Correlate WordPress user role data with course-instructor assignments and flag assignment reviews requested by non-instructors
  • Baseline normal tutor activity per course and alert on cross-course assignment access
  • Enable WordPress audit logging to record assignment view events with user identity and requested assignment ID

Monitoring Recommendations

  • Monitor the Tutor LMS plugin version across all WordPress hosts and alert when versions 3.8.3 or earlier are present
  • Forward web access logs and WordPress audit events to a centralized analytics platform for cross-user behavior analysis
  • Review tutor account provisioning and remove stale or unnecessary tutor-level accounts on a recurring basis

How to Mitigate CVE-2025-6680

Immediate Actions Required

  • Upgrade Tutor LMS to the version that includes changeset 3382577 or later, which adds the missing authorization check
  • Audit tutor-level and higher accounts and remove any that are inactive or unnecessary
  • Review recent assignment access logs for signs of cross-course enumeration by tutor accounts

Patch Information

Themeum addressed the vulnerability by modifying templates/dashboard/assignments/review.php to enforce ownership validation before returning assignment data. Site administrators should update the Tutor LMS plugin to the fixed release referenced in the WordPress Plugin Code Change. Confirm the update through the WordPress plugins dashboard.

Workarounds

  • Restrict the tutor role to trusted staff only until the patch can be applied
  • Temporarily disable the assignments dashboard feature if the plugin allows selective feature toggling
  • Place the WordPress admin dashboard behind IP allow-listing or a web application firewall rule that restricts access to instructional endpoints
bash
# Verify installed Tutor LMS version and update via WP-CLI
wp plugin get tutor --field=version
wp plugin update tutor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.