vulnerability

WordPress Plugin: simple-student-result: CVE-2022-2312: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
Aug 1, 2022
Added
May 15, 2025
Modified
May 15, 2025

Description

The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax actions in versions up to, and including, 1.7.4 due to improper or missing nonce verification. This allows unauthenticated attackers to utilize these ajax actions to add or delete students/employees provided they can trick a contributor or higher-privileged user into clicking on a link. Furthermore, due to insufficient input sanitization of user input, this weakness can be utilized for Stored Cross-Site Scripting.

Solution

simple-student-result-plugin-cve-2022-2312
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.