Extension WordPress
Vulnérabilités Sensei LMS – Online Courses, Quizzes, & Learning
Cette page rassemble les failles publiées pour Sensei LMS – Online Courses, Quizzes, & Learning, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Sensei LMS – Online Courses, Quizzes, & Learning
8 fiches
Sensei LMS <= 4.24.4 – Missing Authorization
The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.24.4. This makes it possible…
*-4.24.4
4.24.5
27/03/2025
Sensei LMS – Online Courses, Quizzes, & Learning <= 4.24.3 – Unauthenticated Information Exposure
The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.24.3 via the sensei_email and sensei_message REST API endpoints. This makes it possible…
*-4.24.3
4.24.4
14/01/2025
Sensei LMS – Online Courses, Quizzes, & Learning <= 4.19.2 – Authenticated (Teacher+) User Email Disclosure
The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.19.2. This makes it possible for authenticated attackers, with Teacher-level access and above,…
*-4.19.2
4.20.0
20/08/2024
Sensei LMS – Online Courses, Quizzes, & Learning <= 4.24.1 – Unauthenticated Email Template Disclosure
The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.24.1 via the /v2/sensei_email/ REST API endpoint due to a missing capability check. This…
*-4.24.1
4.24.2
14/08/2024
Sensei LMS <= 4.23.1 & Sensei Pro (WC Paid Courses) <= 4.24.0.1.24.0 – Missing Authorization
The Sensei LMS and Sensei Pro (WC Paid Courses) plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flush_rewrite_rules() function in versions up to, and including, 4.23.1 and .…
*-4.23.1
4.24.0
06/06/2024
Sensei LMS <= 4.17.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Sensei LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.17.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.17.0
4.18.0
22/12/2023
Sensei LMS <= 4.5.1 – Missing Authorization
The Sensei LMS plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.5.1. This is because the plugin does not properly authenticate individuals before they send emails through the system. This makes it…
*-4.5.1
4.5.2
04/08/2022
Sensei LMS <= 4.4.3 – Information Disclosure
The Sensei LMS plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.4.3. This is due to missing permission checks on one of its REST endpoints and allows unauthenticated attackers to extract…
*-4.4.3
4.5.0
04/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.