CVE Vulnerabilities

CVE-2024-7786

Published: Sep 04, 2024 | Modified: Oct 07, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Affected Software

NameVendorStart VersionEnd Version
Sensei_lmsAutomattic*4.24.2 (excluding)

References