Extracts data from the WordPress database through a time-based blind SQL injection in the Tutor LMS plugin's checkout coupon code parameter. No authentication required.
Is your app exploitable through CVE-2025-13673?