Vulnerabilities
Vulnerable Software
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
CVSS Score
7.5
EPSS Score
0.001
Published
2025-05-15
The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-02-04
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
CVSS Score
5.3
EPSS Score
0.28
Published
2024-09-04
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-02-12


Contact Us

Shodan ® - All rights reserved