PoC Index

CVE-2022-2034

MEDIUM 5.3EPSS 2.5%

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.53% chance of exploitation in the next 30 days, 84th percentile
Nuclei
medium · CWE-639
Published
2022-08-29
Updated
2024-08-03

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related