CVE-2022-2379 is a critical authorization bypass vulnerability affecting the Easy Student Results WordPress plugin up to version 2.2.8. This flaw allows unauthenticated attackers to access sensitive student data, including grades, PII, and course information, via the plugin's REST API. With a CVSS score of 7.5 (HIGH), exploitation is straightforward, requiring no user interaction or privileges, and can lead to a complete compromise of confidentiality. While there is no evidence of active exploitation in the wild, a Nuclei template exists for detection, and the vulnerability has garnered some community discussion, indicating potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.8CPE matchmatch criteria | cpe:2.3:a:easy_student_results_project:easy_student_results:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.