WordPress Plugin Vulnerabilities

Sensei LMS < 4.24.2 - Unauthenticated Email Template Leak

Description

The plugin does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Proof of Concept

Affects Plugins

Fixed in 4.24.2

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Sushmita Poudel
Submitter
Sushmita Poudel
Submitter website
Verified
Yes

Timeline

Publicly Published
2024-08-14 (about 1 year ago)
Added
2024-08-14 (about 1 year ago)
Last Updated
2025-08-26 (about 4 months ago)

Other