All verified exploits

CVE-2025-13673 Unauthenticated SQL Injection via Coupon Code

Deterministic high WordPress Added cve-verified-cve-2025-13673

Extracts data from the WordPress database through a time-based blind SQL injection in the Tutor LMS plugin's checkout coupon code parameter. No authentication required.

Related WordPress exploits

Is your app exploitable through CVE-2025-13673?

Scan your domain free