Missing Authorization in Automattic Sensei LMS Plugin
CVE-2025-22740
5.3MEDIUM
What is CVE-2025-22740?
A missing authorization vulnerability exists in the Automattic Sensei LMS plugin, allowing attackers to exploit insufficient access control. This can lead to unauthorized access to certain functionalities, impacting overall security. This issue affects versions of Sensei LMS prior to 4.24.4 and can potentially jeopardize sensitive data if improperly configured.
Affected Version(s)
Sensei LMS 0 <= 4.24.4
