MediaWiki Incorrect Authorization Vulnerability - CVE-2023-22945
In the GrowthExperiments extension for MediaWiki through 1.39 the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.