CVE-2025-22740: WordPress Sensei LMS plugin <= 4.24.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Automattic Sensei LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through 4.24.4.
Other sources
Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through <= 4.24.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22740?
CVE-2025-22740 is classified as a missing authorization vulnerability affecting certain versions of Automattic Sensei LMS.
How do I fix CVE-2025-22740?
To fix CVE-2025-22740, update Automattic Sensei LMS to a version later than 4.24.4 where the issue has been addressed.
What versions of Automattic Sensei LMS are affected by CVE-2025-22740?
Automattic Sensei LMS versions from n/a through 4.24.4 are affected by CVE-2025-22740.
What are the risks associated with CVE-2025-22740?
The risks associated with CVE-2025-22740 include potential unauthorized access to sensitive areas of the LMS due to improper access controls.
Is there a workaround for CVE-2025-22740 before applying the fix?
Currently, there are no established workarounds for CVE-2025-22740, so updating the software is crucial to mitigate the vulnerability.