Record summary

CVE-2022-2379 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Easy Student Results

CVE List2.2.8 to ≤ 2.2.8affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Easy Student Results <=2.2.8 - Improper AuthorizationCVSS 7.5

WordPress Easy Student Results plugin through 2.2.8 is susceptible to information disclosure. The plugin lacks authorization in its REST API, which can allow an attacker to retrieve sensitive information related to courses, exams, and departments, as well as student grades and information such as email address, physical address, and phone number.

Impact

An attacker can gain access to sensitive student information, potentially compromising their privacy and security.

Remediation

Update to the latest version of the WordPress Easy Student Results plugin (2.2.8) to fix the improper authorization vulnerability.

WeaknessesCWE-862
Authorstheamanrawat
Template tagscvecve2022wordpresswp-pluginwpeasy-student-resultsdisclosurewpscaneasy_student_results_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:easy_student_results_project:easy_student_results:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2