Showing 2 vulnerabilities on this page for sensei_lms

Signals CISA KEV Ransomware Nuclei
Automattic vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Sensei LMS < 4.24.2 - Unauthenticated Email Template Leak

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

CWE-862Sep 4, 20241 related artifact
CVSS7.5v3.1EPSS1.64%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

CWE-862Aug 18, 2024
CVSS5.3v3.1EPSS0.525%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX