Automattic

Sensei Lms

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 15.05.2025 20:15:57
  • Zuletzt bearbeitet 11.06.2025 16:14:04

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

  • EPSS 0.04%
  • Veröffentlicht 27.03.2025 21:20:58
  • Zuletzt bearbeitet 28.03.2025 18:11:40

Missing Authorization vulnerability in Automattic Sensei LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through 4.24.4.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 04.02.2025 06:15:30
  • Zuletzt bearbeitet 30.09.2025 18:16:39

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

Exploit
  • EPSS 32.77%
  • Veröffentlicht 04.09.2024 06:15:17
  • Zuletzt bearbeitet 07.10.2024 17:46:08

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

  • EPSS 0.07%
  • Veröffentlicht 18.08.2024 22:15:07
  • Zuletzt bearbeitet 19.08.2024 12:59:59

Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

  • EPSS 0.07%
  • Veröffentlicht 12.02.2024 07:15:08
  • Zuletzt bearbeitet 21.11.2024 08:37:27

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: f...

Exploit
  • EPSS 51.37%
  • Veröffentlicht 29.08.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:12

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

Exploit
  • EPSS 0.24%
  • Veröffentlicht 29.08.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:17

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note...