HomeDefault status
unaffected
Any version before 4.20.0
affected
Description
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 4.20.0
Credits
Li Xuhang
WPScan
References
wpscan.com/...rability/737bb010-b2fa-4bf4-b124-5fbba67cf935/