RULE(RULE ID:336635)

Rule General Information
Release Date: 2022-06-09
Rule Name: WordPress Weblizar Backdoor Vulnerability (CVE-2022-1609)
Severity:
CVE ID:
Rule Protection Details
Description: Weblizar School Management Pro is a WordPress plugin from the Indian company weblizar. Used to manage the school and its entities. A code injection vulnerability exists in School Management Pro versions 6.0 to 9.9.6, which originates from an obscure backdoor issue in the REST API, which can be exploited by a remote attacker to execute arbitrary code on the target system.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://www.cybersecurity-help.cz/vdb/SB2022052325
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://wpscan.com/vulnerability/e2d546c9-85b6-47a4-b951-781b9ae5d0f2