PT-2025-13397 · Automattic · Automattic Sensei Lms

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-22740

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Automattic Sensei LMS versions 4.24.4 and earlier
Description The issue is related to a Missing Authorization vulnerability, which allows exploiting incorrectly configured access control security levels.
Recommendations For Automattic Sensei LMS versions 4.24.4 and earlier, update to a version later than 4.24.4 to resolve the issue.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22740

Affected Products

Automattic Sensei Lms