Medium severity4.3NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026
CVE-2022-2080
CVE-2022-2080
Description
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<4.5.2+ 1 more
- (no CPE)range: <4.5.2
- (no CPE)
Patches
Vulnerability mechanics
References
2- hackerone.com/reports/1592596nvdExploitThird Party Advisory
- wpscan.com/vulnerability/5395d196-a39a-4a58-913e-5b5b9d6123a5nvdThird Party Advisory
News mentions
0No linked articles in our index yet.