CVE-2024-8009: Sensei LMS < 4.20.0 - Teacher+ Users Email Address Disclosure
Published May 15, 2025
·Updated
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
Affected Software
2 affected components
Sensei LMS<4.20.0
Automattic Sensei Lms Wordpress<4.20.0
Event History
May 15, 2025
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8009?
CVE-2024-8009 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-8009?
To fix CVE-2024-8009, update the Sensei LMS WordPress plugin to version 4.20.0 or later.
3
What systems are affected by CVE-2024-8009?
CVE-2024-8009 affects Sensei LMS versions prior to 4.20.0.
4
What type of data is exposed in CVE-2024-8009?
CVE-2024-8009 discloses all users of the blog, including their email addresses, to teachers on the students page.
5
Who can exploit CVE-2024-8009?
CVE-2024-8009 can be exploited by any teacher with access to the students page in the Sensei LMS.