CVE-2025-13673 is an SQL injection vulnerability in the Tutor LMS – eLearning and online course solution plugin for WordPress. According to the provided content, all versions up to and including 3.9.6 are affected. The flaw is present in handling of the user-controlled 'coupon_code' parameter, caused by insufficient escaping of attacker-supplied input and inadequate preparation of the SQL query before execution. This allows crafted input to be appended to an existing SQL statement, enabling unauthorized database query manipulation. The issue was only partially mitigated in versions 3.9.4 and 3.9.6, indicating those releases did not fully eliminate the vulnerable condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained exploit lab for CVE-2025-13673 affecting the Tutor LMS WordPress plugin. It contains one main exploit script (exploit.py), one lab deployment script (setup.sh), a Docker Compose environment, and documentation. The exploit is real and operational rather than a simple detector. The core capability is SQL injection through the coupon_code parameter. The Python exploit supports two modes: unauthenticated time-based blind SQLi and authenticated UNION-based SQLi. It fingerprints the target by requesting /wp-content/plugins/tutor/readme.txt, parses the Tutor LMS version, and distinguishes between fully exploitable versions (described in the code as <= 3.9.3), partially mitigated versions (3.9.4-3.9.6), and fixed versions (>= 3.9.7). It also retrieves a _tutor_nonce from public frontend pages such as / and /courses/, and can establish an authenticated WordPress session when credentials are supplied. The unauthenticated path uses POST / with tutor_action=tutor_pay_now and time-based payloads built around SLEEP() and IF(condition,SLEEP(n),0). This mode is intended to confirm injection and extract data slowly via blind inference. The authenticated path targets /wp-admin/admin-ajax.php with action=tutor_apply_coupon and uses UNION SELECT payloads to reflect query results directly in JSON responses, enabling faster extraction of user credentials, database info, and WordPress options. Repository structure and purpose: - exploit.py: Main PoC/exploit. Implements version detection, nonce extraction, login/session handling, SQLi verification, and data extraction routines. - setup.sh: Builds a local vulnerable lab, installs WordPress, downloads a chosen Tutor LMS version, enables registration/coupons/monetization, and creates test users and a paid course. - docker-compose.yml: Defines MySQL and WordPress containers, exposing ports 3307 and 8080. - README.md: Documents the vulnerability, attack vectors, usage examples, and lab workflow. Overall, this repository is designed both as an educational lab and as a practical exploit PoC for testing Tutor LMS SQL injection exposure, with explicit support for target fingerprinting and post-confirmation database extraction.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.