plugin

Sensei Lms Vulnerabilities

16 known security issues reported for the Sensei Lms WordPress plugin. Most recent disclosed Mar 27, 2025.

8 medium

Running Sensei Lms on your site? Check whether your installed version is affected.

Scan your site free

Sensei LMS <= 4.24.4 - Missing Authorization

medium

The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.24.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.24.4
Fixed in:
4.24.5
Disclosed:
Mar 27, 2025

CVE-2025-22740 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.24.5

unknown

[en] Missing Authorization vulnerability in Automattic Sensei LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through 4.24.4.

Affected:
up to 4.24.5
Fixed in:
4.24.5
Disclosed:
Mar 27, 2025

CVE-2025-22740 on NVD →

Sensei LMS – Online Courses, Quizzes, & Learning <= 4.24.3 - Unauthenticated Information Exposure

medium

The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.24.3 via the sensei_email and sensei_message REST API endpoints. This makes it possible for unauthenticated attackers to extract sensitive data including emai...

CVSS:
5.3
Affected:
up to 4.24.3
Fixed in:
4.24.4
Disclosed:
Jan 14, 2025

CVE-2025-0466 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.24.2

unknown

[en] The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Affected:
up to 4.24.2
Fixed in:
4.24.2
Disclosed:
Sep 4, 2024

CVE-2024-7786 on NVD →

Sensei LMS – Online Courses, Quizzes, & Learning <= 4.19.2 - Authenticated (Teacher+) User Email Disclosure

medium

The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.19.2. This makes it possible for authenticated attackers, with Teacher-level access and above, to view other user's email addresses.

CVSS:
5.3
Affected:
up to 4.19.2
Fixed in:
4.20.0
Disclosed:
Aug 20, 2024

CVE-2024-8009 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.24.0

unknown

[en] Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

Affected:
up to 4.24.0
Fixed in:
4.24.0
Disclosed:
Aug 18, 2024

CVE-2024-35686 on NVD →

Sensei LMS – Online Courses, Quizzes, & Learning <= 4.24.1 - Unauthenticated Email Template Disclosure

medium

The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.24.1 via the /v2/sensei_email/ REST API endpoint due to a missing capability check. This makes it possible for unauthenticated attackers to extract data from email temp...

CVSS:
5.3
Affected:
up to 4.24.1
Fixed in:
4.24.2
Disclosed:
Aug 14, 2024

CVE-2024-7786 on NVD →

Sensei LMS <= 4.23.1 & Sensei Pro (WC Paid Courses) <= 4.24.0.1.24.0 - Missing Authorization

medium

The Sensei LMS and Sensei Pro (WC Paid Courses) plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flush_rewrite_rules() function in versions up to, and including, 4.23.1 and . 4.24.0.1.24.0 respectively. This makes it possible for unauthenticated attackers...

CVSS:
5.3
Affected:
up to 4.23.1
Fixed in:
4.24.0
Disclosed:
Jun 6, 2024

CVE-2024-35686 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.18.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.

Affected:
up to 4.18.0
Fixed in:
4.18.0
Disclosed:
Feb 12, 2024

CVE-2023-50875 on NVD →

Sensei LMS <= 4.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sensei LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.17.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 4.17.0
Fixed in:
4.18.0
Disclosed:
Dec 22, 2023

CVE-2023-50875 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.5.0

unknown

[en] The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

Affected:
up to 4.5.0
Fixed in:
4.5.0
Disclosed:
Aug 29, 2022

CVE-2022-2034 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.5.2

unknown

[en] The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the te...

Affected:
up to 4.5.2
Fixed in:
4.5.2
Disclosed:
Aug 29, 2022

CVE-2022-2080 on NVD →

Sensei LMS <= 4.4.3 - Information Disclosure

medium

The Sensei LMS plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.4.3. This is due to missing permission checks on one of its REST endpoints and allows unauthenticated attackers to extract sensitive data including private messages sent to teachers.

CVSS:
5.3
Affected:
up to 4.4.3
Fixed in:
4.5.0
Disclosed:
Aug 4, 2022

CVE-2022-2034 on NVD →

Sensei LMS <= 4.5.1 - Missing Authorization

medium

The Sensei LMS plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.5.1. This is because the plugin does not properly authenticate individuals before they send emails through the system. This makes it possible for attackers to send emails to arbitrary users and impersonate oth...

CVSS:
4.3
Affected:
up to 4.5.1
Fixed in:
4.5.2
Disclosed:
Aug 4, 2022

CVE-2022-2080 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.24.4

unknown
Affected:
up to 4.24.4
Fixed in:
4.24.4

CVE-2025-0466 on NVD →

Sensei LMS &#8211; Online Courses, Quizzes, &amp; Learning [sensei-lms] < 4.20.0

unknown
Affected:
up to 4.20.0
Fixed in:
4.20.0

CVE-2024-8009 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database