WordPress Sensei LMS plugin <= 4.5.1 - Arbitrary Private Message Sending via IDOR vulnerability
PSID
63a67b1bd2a3
Classification
Insecure Direct Object References (IDOR)
OWASP Top 10
A5: Broken Access Control
Required privilege
Requires low role user authentication.
Publicly disclosed
2022-08-04
Patchstack vPatch available since
09.12.2021
Details
Arbitrary Private Message Sending via IDOR vulnerability discovered by Veshraj Ghimire in WordPress Sensei LMS plugin (versions <= 4.5.1).
Solution
Update the WordPress Sensei LMS plugin to the latest available version (at least 4.5.2).
References
Vulnerability details