Sensei LMS
cpe:2.3:a:automattic:sensei_lms:*:*:*:*:wordpress:*:*
- < 4.20.0
A vulnerability in the Sensei LMS WordPress plugin, affecting versions prior to 4.20.0, allows for the disclosure of all blog users and their email addresses to teachers on the students page. This issue arises from improper authorization, enabling unauthorized access to sensitive user information.
Exploitation of this vulnerability leads to unauthorized disclosure of user email addresses to teachers within the Sensei LMS environment.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.