5.3 CVE-2025-0466

Enriched by CISA Exploit
 

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.
https://nvd.nist.gov/vuln/detail/CVE-2025-0466

Categories

CWE-NVD-noinfo

References

contact@wpscan.com Exploit


 

AFFECTED (from MITRE)


Vendor Product Versions
Unknown Sensei LMS
  • < 4.24.4 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:wordpress:*:* < 4.24.4


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
https://wpscan.com/vulnerability/53ab86dc-1195-4ba0-8eda-6a0d7b45c45f/


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry