Sensei LMS
cpe:2.3:a:automattic:sensei_lms:*:*:*:*:wordpress:*:*
- < 4.24.4
A vulnerability exists in the Sensei LMS WordPress plugin in versions prior to 4.24.4, where certain REST API routes are not adequately protected. This flaw allows unauthenticated attackers to access and leak sensitive information, specifically the 'sensei_email' and 'sensei_message' data.
Exploitation of this vulnerability leads to unauthorized access and disclosure of sensitive user information, including email addresses and message content, from the affected WordPress site.
Users are advised to update the Sensei LMS WordPress plugin to version 4.24.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.