CVE-2025-13628

Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.


We have discovered 7,927 live websites that are affected by CVE-2025-13628.

Run a Free Instant Scan




Affected Software

Product  Tutor LMS
Category Learning Management System
Vulnerable Domains7,927 live websites (93% of Tutor LMS install base)
Vulnerable Versions
  • from 0 through 3.9.3
Vulnerable Versions Count118 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 9, 2026
  • Updated - Jan 9, 2026

Credits

  • Supakiad S. (finder)

Website Distribution by Country

Number of websites using CVE-2025-13628
United States2,223 websites



Germany627 websites
Cyprus452 websites
India385 websites
France356 websites
Poland354 websites
GB336 websites
Brazil297 websites
Italy222 websites
Spain194 websites

Website Distribution by TLD

Number of websites using CVE-2025-13628
.com3,778 websites
.org488 websites
.pl270 websites
.com.br245 websites
.de172 websites
.net161 websites
.it146 websites
.co.uk133 websites
.fr116 websites
.nl102 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13628

Top websites that are affected by CVE-2025-13628. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*****.com France***,***
*****.co Cyprus***,***
****.nl Netherlands***,***
*****.es Spain***,***
****.me United Arab Emirates***,***
***.gr Greece***,***
********.com Cyprus***,***
***********.com United States***,***
**********.ee Estonia***,***
See full domain list

FAQ

CVE-2025-13628 is Missing Authorization in Tutor LMS
A total of 7,927 websites have been identified as vulnerable to CVE-2025-13628, based on global website indexing conducted by WebTechSurvey.
The Tutor LMS is affected by the CVE-2025-13628 vulnerability.
Tutor LMS versions up to and including 3.9.3 are vulnerable to CVE-2025-13628.