WordPress Sensei LMS plugin before 4.5.0 is susceptible to information disclosure. The plugin does not have proper permissions set in a REST endpoint, which can allow an attacker to access private messages.
id: CVE-2022-2034
info:
name: WordPress Sensei LMS <4.5.0 - Information Disclosure
author: imhu
...