WordPress Plugin Vulnerabilities
Student Result or Employee Database < 1.6.4 - Auth Bypass
Description
The plugin does not have authorisation checks in its AJAX actions, allowing unauthenticated users to perform unauthorised actions such as add students
Proof of Concept
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Benjamin Lim
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2017-09-21 (about 8 years ago)
Added
2017-09-28 (about 8 years ago)
Last Updated
2022-07-27 (about 3 years ago)