CVE-2024-35686: WordPress Sensei LMS plugin <= 4.23.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35686?
CVE-2024-35686 is classified as a Missing Authorization vulnerability that can lead to unauthorized access within the affected plugins.
How do I fix CVE-2024-35686?
To fix CVE-2024-35686, you should update Automattic Sensei LMS and Sensei Pro (WC Paid Courses) to versions 4.23.2 or later.
Which versions are affected by CVE-2024-35686?
CVE-2024-35686 affects Sensei LMS from n/a through 4.23.1 and Sensei Pro from n/a through 4.23.1.1.
What products are impacted by CVE-2024-35686?
CVE-2024-35686 impacts Automattic Sensei LMS and Automattic Sensei Pro (WC Paid Courses) plugins.
Is CVE-2024-35686 exploitable in my environment?
If you are using the affected versions of Sensei LMS or Sensei Pro, then CVE-2024-35686 is exploitable in your environment.