CVE Vulnerabilities

CVE-2024-7786

Published: Sep 04, 2024 | Modified: Oct 07, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Affected Software

Name Vendor Start Version End Version
Sensei_lms Automattic * 4.24.2 (excluding)

References