WordPress Sensei LMS plugin before 4.5.0 is susceptible to information disclosure. The plugin does not have proper permissions set in a REST endpoint, which can allow an attacker to access private messages.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view