plugin

Simple Student Result Vulnerabilities

3 known security issues reported for the Simple Student Result WordPress plugin. Most recent disclosed Aug 1, 2022.

1 critical 1 high 1 medium

Running Simple Student Result on your site? Check whether your installed version is affected.

Scan your site free

Student Result or Employee Database <= 1.7.9 - Missing Authorization

high

The Student Results or Employee Database plugin for WordPress is vulnerable to unauthorized REST calls in versions up to, and including 1.7.9. This is due to flawed permission callback in the plugin's REST endpoints. This makes it possible for unauthenticated attackers to utilize these endpoints to add, modify or delet...

CVSS:
7.2
Affected:
up to 1.7.9
Fixed in:
1.8.0
Disclosed:
Aug 1, 2022

Student Result or Employee Database <= 1.7.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax actions in versions up to, and including, 1.7.4 due to improper or missing nonce verification. This allows unauthenticated attackers to utilize these ajax actions to add or delete students/employees prov...

CVSS:
6.1
Affected:
up to 1.7.4
Fixed in:
1.7.5
Disclosed:
Aug 1, 2022

CVE-2022-2312 on NVD →

Student Result or Employee Database <= 1.6.3 - Authentication Bypass

critical

The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.

CVSS:
9.8
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Sep 21, 2017

CVE-2017-14766 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database