CVE-2025-6680: Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes it possible for authenticated attackers, with tutor-level access and above, to view assignments for courses they don't teach which may contain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6680?
CVE-2025-6680 is considered a medium severity vulnerability due to potential sensitive information exposure.
How do I fix CVE-2025-6680?
To fix CVE-2025-6680, you should update the Tutor LMS plugin to version 3.8.4 or later.
Who is affected by CVE-2025-6680?
Authenticated users with tutor-level access and above are affected by CVE-2025-6680.
What kind of sensitive information can be exposed in CVE-2025-6680?
CVE-2025-6680 allows for the exposure of assignments within the Tutor LMS plugin.
When was CVE-2025-6680 disclosed?
CVE-2025-6680 was disclosed as a vulnerability in all versions of the Tutor LMS plugin up to and including 3.8.3.