CVE-2024-7786: Automattic Sensei Lms
Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
Affected products
- Automattic Sensei Lms: before 4.24.2 (fixed in 4.24.2)
Published 2024-09-04. Last modified 2026-06-17.