CVE-2024-8009: Automattic Sensei Lms
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
Affected products
- Automattic Sensei Lms: before 4.20.0 (fixed in 4.20.0)
Published 2025-05-15. Last modified 2026-06-17.