WordPress Plugin Vulnerabilities

Student Result or Employee Database < 1.8.0 - Unauthorised REST Calls

Description

The plugin has a flawed permission callback in its REST endpoints, allowing unauthenticated attackers to call them and add/edit/delete arbitrary student for example

Proof of Concept

Affects Plugins

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2022-08-01 (about 3 years ago)
Added
2022-08-01 (about 3 years ago)
Last Updated
2022-08-01 (about 3 years ago)

Other