CVE-2025-64236

9.8

AmentoTech · Tuturn (Online Tutors Marketplace WordPress Theme)

AmentoTech Tuturn WordPress theme contains an authentication bypass vulnerability allowing unauthenticated attackers to gain unauthorized access via an alternate path or channel.

Executive summary

An authentication bypass vulnerability in the AmentoTech Tuturn WordPress theme allows unauthenticated attackers to fully compromise the affected site.

Vulnerability

The vulnerability is an authentication bypass (CWE-288) that allows unauthenticated remote attackers to circumvent standard login procedures and gain unauthorized access to the application.

Business impact

Successful exploitation allows an unauthenticated attacker to bypass authentication, potentially gaining administrative access to the WordPress site. This leads to full site compromise, including the ability to exfiltrate sensitive data, modify content, or inject malicious scripts. While the CVSS score of 9.8 reflects the highest level of severity, the impact is catastrophic for any organization relying on the Tuturn platform for business operations.

Remediation

Immediate Action: Update the AmentoTech Tuturn theme to version 3.6 or later immediately.

Proactive Monitoring: Review web server and WordPress access logs for unusual login patterns or unauthorized administrative actions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting authentication endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the ease of exploitation, immediate patching is required. Administrators should prioritize updating the Tuturn theme to version 3.6 to eliminate the risk of unauthorized access and system takeover.