Student Result or Employee Database <= 1.7.9 - Missing Authorization
high
The Student Results or Employee Database plugin for WordPress is vulnerable to unauthorized REST calls in versions up to, and including 1.7.9. This is due to flawed permission callback in the plugin's REST endpoints. This makes it possible for unauthenticated attackers to utilize these endpoints to add, modify or delet...
- CVSS:
- 7.2
- Affected:
- up to 1.7.9
- Fixed in:
- 1.8.0
- Disclosed:
- Aug 1, 2022
Student Result or Employee Database <= 1.7.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax actions in versions up to, and including, 1.7.4 due to improper or missing nonce verification. This allows unauthenticated attackers to utilize these ajax actions to add or delete students/employees prov...
- CVSS:
- 6.1
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.5
- Disclosed:
- Aug 1, 2022
CVE-2022-2312 on NVD →
Student Result or Employee Database <= 1.6.3 - Authentication Bypass
critical
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.
- CVSS:
- 9.8
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Sep 21, 2017
CVE-2017-14766 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database