The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
- https://wpscan.com/vulnerability/737bb010-b2fa-4bf4-b124-5fbba67cf935/
No PoCs found on GitHub currently.