Sensei Lms Automattic Sensei Lms

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Automattic Sensei Lms.

By the Year

In 2026 there have been 0 vulnerabilities in Automattic Sensei Lms. Last year, in 2025 Sensei Lms had 3 security vulnerabilities published. Right now, Sensei Lms is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 3 4.30
2024 3 5.35
2023 0 0.00
2022 2 4.80

It may take a day or so for new Sensei Lms vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Automattic Sensei Lms Security Vulnerabilities

WP Sensei LMS <4.20.0 - User Email Disclosure to Teachers
CVE-2024-8009 4.3 - Medium - May 15, 2025

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

Sensei LMS v4.24.4: Missing Authorization Vulnerability (CVE-2025-22740)
CVE-2025-22740 - March 27, 2025

Missing Authorization vulnerability in Automattic Sensei LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through 4.24.4.

AuthZ

WordPress Sensei LMS REST API Info Leak (v4.24.4-)
CVE-2025-0466 - February 04, 2025

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

Unauth REST API Email Template Leak in Sensei LMS <4.24.2
CVE-2024-7786 5.3 - Medium - September 04, 2024

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Missing Auth in Automattic Sensei LMS & Pro 4.23.1
CVE-2024-35686 - August 18, 2024

Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

AuthZ

Stored XSS in Automattic Sensei LMS <=4.17.0 (CVE-2023-50875)
CVE-2023-50875 5.4 - Medium - February 12, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS Online Courses, Quizzes, & Learning: from n/a through 4.17.0.

XSS

Sensei LMS WP Plugin <4.5.2 IDOR via Private Message Sender Bypass
CVE-2022-2080 4.3 - Medium - August 29, 2022

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student

Insecure Direct Object Reference / IDOR

Sensei LMS WP Plugin 4.5.0 Unauth Access via REST Endpoint
CVE-2022-2034 5.3 - Medium - August 29, 2022

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

Insecure Direct Object Reference / IDOR

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Automattic Sensei Lms or by Automattic? Click the Watch button to subscribe.

Automattic
Vendor

subscribe