CVE-2017-14766: Saadamin Simple Student Result
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.
Affected products
- Saadamin Simple Student Result: up to and including 1.6.3
Published 2017-09-27. Last modified 2026-06-17.