### [CVE-2022-2034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2034) ![](https://img.shields.io/static/v1?label=Product&message=Sensei%20LMS&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%204.5.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brighgreen) ### Description The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers ### POC #### Reference - https://wpscan.com/vulnerability/aba3dd58-7a8e-4129-add5-4dd5972c0426 #### Github - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/soxoj/information-disclosure-writeups-and-pocs