The Sensei LMS  WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
Affected Software
| Name | 
Vendor | 
Start Version | 
End Version | 
| Sensei_lms | 
Automattic | 
* | 
4.24.2 (excluding) | 
References