'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-06-29 | |
| Rule Name: | WordPress Easy Student Results Information Disclosure Vulnerability (CVE-2022-2379) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc | |
| Impact: | Unauthenticated attackers can access sensitive student information including grades, personal details (email, address, phone), course data, and exam results through publicly accessible REST API endpoints, leading to potential identity theft and social engineering attacks. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://wpscan.com/vulnerability/0773ba24-212e-41d5-9ae0-1416ea2c9db6 |
|
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |