The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Sensei_lms |
Automattic |
* |
4.24.2 (excluding) |
References