CVE-2025-3625: Moodle

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

Affected products

  • Moodle Moodle: from 4.3.0, before 4.3.12 (fixed in 4.3.12); from 4.4.0, before 4.4.8 (fixed in 4.4.8); from 4.5.0, before 4.5.4 (fixed in 4.5.4)

Published 2025-04-25. Last modified 2026-06-17.