CVE-2025-0466
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 4, 2025
Summary
CVE-2025-0466 is a vulnerability affecting the Sensei LMS WordPress plugin before version 4.24.4. This issue permits unauthenticated attackers to access sensitive information, specifically sensei_email and sensei_message data, through unprotected REST API routes. This vulnerability poses a significant risk for WordPress sites using the Sensei LMS plugin, as it can lead to data exposure. Site administrators are advised to update to the latest plugin version to mitigate this vulnerability and secure their data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share