WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability
Published Aug 18, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.63%
Description
Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.
Affected products
-
Affected
- ≤ 4.23.1
-
Affected
- ≤ 4.23.1.1.23.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Automattic | Sensei LMS | unaffected | Affected
|
| Automattic | Sensei Pro (WC Paid Courses) | unaffected | Affected
|
No data.
-
Affected
- ≥ 0, ≤ 4.23.1
-
Affected
- ≥ 0, ≤ 4.23.1.1.23.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Automattic | Sensei Lms | unaffected | Affected
|
| Automattic | Sensei Pro | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update Sensei LMS to 4.24.0 or a higher version.
Update Sensei Pro (WC Paid Courses) to 4.24.0.1.24.0 or a higher version.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-35445 Advisory
- https://patchstack.com/database/vulnerability/sensei-lms/wordpress-sensei-lms-plugin-4-23-1-broken-access-control-vulnerability?_s_id=cve vdb-entry
- https://patchstack.com/database/vulnerability/woothemes-sensei/wordpress-sensei-pro-wc-paid-courses-plugin-4-23-1-1-23-1-broken-access-control-vulnerability?_s_id=cve vdb-entry
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data