The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
History

Wed, 11 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic sensei Lms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:wordpress:*:*
Vendors & Products Automattic
Automattic sensei Lms

Fri, 16 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
Title Sensei LMS < 4.20.0 - Teacher+ Users Email Address Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:09:47.142Z

Updated: 2025-05-16T15:17:15.222Z

Reserved: 2024-08-20T12:29:53.471Z

Link: CVE-2024-8009

cve-icon Vulnrichment

Updated: 2025-05-16T15:17:06.347Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:57.260

Modified: 2025-06-11T16:14:04.737

Link: CVE-2024-8009

cve-icon Redhat

No data.