CVE-2025-13673Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was partially mitigated in versions 3.9.4 and 3.9.6.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-28); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-28: 2Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-05-24: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-05-24: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-05-24: 102-2803-0303-0505-24
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-282
Disclosure1General1
2026-03-031
PoC1
2026-03-051
Disclosure1
2026-05-241
PoC1
Full discourse5 posts
  • Nicolas Krassas@Dinosn
    PoC

    Unauthenticated SQL Injection in Tutor LMS WordPress plugin (<= 3.9.6) via the coupon_code parameter. https://github.com/dinosn/CVE-2025-13673

    Post summary

    The tweet discloses an unauthenticated SQL injection vulnerability (CVE-2025-13673) in Tutor LMS WordPress plugin versions up to 3.9.6 and provides a GitHub link likely containing a proof‑of‑concept exploit.

    0201462.0K
    158.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-13673 (CVSS:7.5, HIGH) is Awaiting Analysis. The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon..https://nvd.nist.gov/vuln/detail/CVE-2025-13673 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-13673 is identified as a high‑severity SQL injection vulnerability in Tutor LMS, but the post offers no PoC, exploit, or patch details.

    0000037
    173 followersView on X
  • norahc@viii_norahc
    PoC

    #POC CVE-2025-13673: Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection Software Downloads: 3.845.062 Software Active Installs: 100.000 POC: Follow & cmt "Me 📧" https://t.co/GKjyvPcCxQ

    Post summary

    A PoC for CVE-2025-13673, an unauthenticated SQL injection in Contest Gallery versions up to 28.1.4, is shared with a link.

    00000133
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13673 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2025-13673

    Post summary

    CVE-2025-13673 exposes a SQL injection flaw in the Tutor LMS WordPress plugin through the 'coupon_code' parameter, affecting all versions up to the latest.

    00000169
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-13673 SQL Injection in Tutor LMS WordPress Plugin via Unauthenticated Coupon Code Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13673

    Post summary

    The text identifies CVE-2025-13673 as a SQL injection flaw in the Tutor LMS WordPress plugin but offers no evidence of a PoC, exploit code, active exploitation, or patch information.

    0000093
    4.0K followersView on X

Explore more