The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.
We have discovered 7,927 live websites that are affected by CVE-2025-13628.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 7,927 live websites (93% of Tutor LMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 118 versions ( 99% of all versions) |
| 2,223 websites | |
| 627 websites | |
| 452 websites | |
| 385 websites | |
| 356 websites | |
| 354 websites | |
| 336 websites | |
| 297 websites | |
| 222 websites | |
| 194 websites |
| .com | 3,778 websites |
| .org | 488 websites |
| .pl | 270 websites |
| .com.br | 245 websites |
| .de | 172 websites |
| .net | 161 websites |
| .it | 146 websites |
| .co.uk | 133 websites |
| .fr | 116 websites |
| .nl | 102 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | **,*** | ||
| *****.com | ***,*** | ||
| *****.co | ***,*** | ||
| ****.nl | ***,*** | ||
| *****.es | ***,*** | ||
| ****.me | ***,*** | ||
| ***.gr | ***,*** | ||
| ********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| **********.ee | ***,*** |
FAQ