CVE-2025-11564
BaseFortify
Publication date: 2025-10-25
Last updated on: 2025-12-05
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| themeum | tutor_lms | to 3.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Tutor LMS WordPress plugin up to version 3.8.3, where a missing capability check in the verifyAndCreateOrderData function allows unauthenticated attackers to bypass payment verification. Attackers can submit forged webhook requests with the payment_type set to 'recurring' to mark orders as paid without authorization.
How can this vulnerability impact me? :
The vulnerability can allow attackers to fraudulently mark orders as paid without actually completing payment. This can lead to unauthorized access to paid content or services, financial losses, and potential disruption of business operations.