VulnerabilityAnalyzed
CVE-2024-7786
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
MEDIUM 5.3EPSS 1.75%
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- automattic/sensei lms
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/f44e6f8f-3ef2-45c9-ae9c-9403305a548a/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.