Back

MEDIUM

WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability

Published Aug 18, 2024

Description

Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

Affected products

Remediation

Vendor solution

Update Sensei LMS to 4.24.0 or a higher version.

Update Sensei Pro (WC Paid Courses) to 4.24.0.1.24.0 or a higher version.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Patchstack
Published Aug 18, 2024
Updated Apr 28, 2026
Reserved May 17, 2024

CISA Vulnrichment

Updated Aug 19, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Patchstack
Published Aug 18, 2024
Updated Apr 28, 2026

GitHub

No data