---
id: CVE-2025-6680
title: >-
  The Tutor LMS – eLearning and online course solution plugin for WordPress is
  vulnerable to Sensitive Information Exposure in all versions up to, and
  including, 3.8.3
summary: >-
  The Tutor LMS – eLearning and online course solution plugin for WordPress is
  vulnerable to Sensitive Information Exposure in all versions up to, and
  including, 3.8.3. This makes it possible for authenticated attackers, with
  tutor-level a…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-284
vendor: themeum
product: tutor_lms
affected:
  - tutor_lms < 3.9.0
patched:
  - tutor_lms 3.9.0
published: '2025-10-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6680'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3382577/tutor/trunk/templates/dashboard/assignments/review.php?old=3249440&old_path=tutor%2Ftrunk%2Ftemplates%2Fdashboard%2Fassignments%2Freview.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/1b8d88e4-a9dc-4740-b836-99f730beefcb?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00216
epssPercentile: 0.10995
ingestedAt: '2026-10-08T11:31:27.581Z'
---

## Overview

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes it possible for authenticated attackers, with tutor-level access and above, to view assignments for courses they don't teach which may contain sensitive information.

## Affected

- `tutor_lms < 3.9.0`

## Remediation

Upgrade past the affected range:

- `tutor_lms 3.9.0`
