CVE-2025-11564: Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webhook signatures on the "verifyAndCreateOrderData" function in all versions up to, and including, 3.8.3. This makes it possible for unauthenticated attackers to bypass payment verification and mark orders as paid by submitting forged webhook requests with paymenttype set to 'recurring'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11564?
The severity of CVE-2025-11564 is considered moderate due to potential unauthorized data modification.
How do I fix CVE-2025-11564?
To fix CVE-2025-11564, update the Tutor LMS plugin to version 3.8.4 or later, which includes the necessary capability checks.
Which versions are affected by CVE-2025-11564?
CVE-2025-11564 affects all versions of the Tutor LMS plugin up to and including 3.8.3.
What impacts can CVE-2025-11564 have on my site?
CVE-2025-11564 can allow unauthorized users to modify order data, potentially affecting transactions and user data integrity.
Is CVE-2025-11564 exploitable remotely?
Yes, CVE-2025-11564 can be exploited remotely due to the nature of the webhook signature verification vulnerability.