Record summary

CVE-2022-2034 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Sensei LMS

Default status: unaffected

CVE ListBefore 4.5.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Sensei LMS <4.5.0 - Information DisclosureCVSS 5.3

WordPress Sensei LMS plugin before 4.5.0 is susceptible to information disclosure. The plugin does not have proper permissions set in a REST endpoint, which can allow an attacker to access private messages.

Impact

Unauthenticated attackers can access private Sensei LMS messages via unprotected REST API endpoints, potentially exposing confidential student-teacher communications.

Remediation

Upgrade WordPress Sensei LMS to version 4.5.0 or later to mitigate this vulnerability.

WeaknessesCWE-639
Authorsimhunterand
Template tagscvecve2022wpdisclosurewpscansensei-lmsfuzzhackeronewordpresswp-pluginautomatticvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3