CVE-2025-3634: Moodle
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
Affected products
- Moodle Moodle: from 4.3.0, before 4.3.12 (fixed in 4.3.12); from 4.4.0, before 4.4.8 (fixed in 4.4.8); from 4.5.0, before 4.5.4 (fixed in 4.5.4)
Published 2025-04-25. Last modified 2026-06-17.