Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Li Xuhang

#26622of 53,635
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-21506
4.3
2025-05-15
WordPress · Sensei Lms · CVE-2024-8009
Name of the Vulnerable Software and Affected Versions: The Sensei LMS WordPress plugin versions prior to 4.20.0 Description: The issue allows disclosure of all users of the blog, including their email addresses, to teachers on the students page. Recommendations: For versions prior to 4.20.0, update to version 4.20.0 or later to resolve the issue.
PT-2025-3902
5.3
2025-02-04
WordPress · Sensei Lms · CVE-2025-0466
**Name of the Vulnerable Software and Affected Versions** Sensei LMS WordPress plugin versions prior to 4.24.4 **Description** The issue concerns the inadequate protection of some REST API routes in the Sensei LMS WordPress plugin, allowing unauthenticated attackers to leak information related to `sensei email` and `sensei message`. **Recommendations** For Sensei LMS WordPress plugin versions prior to 4.24.4, update to version 4.24.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable REST API routes until a patch is applied.