Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpschoolpress MEDIUM 6.5
CVE-2025-1669

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, an…

Fix: after 2.2.16
Fix from $1,600 2025-03-15
Wpschoolpress MEDIUM 6.5
CVE-2025-1670

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i…

Fix: after 2.2.16
Fix from $1,600 2025-03-15
Wpschoolpress MEDIUM 5.4
CVE-2025-1668

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the w…

Fix: after 2.2.16
Fix from $1,600 2025-03-15
Wpschoolpress MEDIUM 6.5
CVE-2024-12332

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i…

Fix: after 2.2.14
Fix from $1,600 2025-01-07
Wpschoolpress HIGH 8.8
CVE-2024-9637

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, a…

Fix: 2.2.11+
Fix from $1,950 2024-10-26
Wpschoolpress HIGH 8.8
CVE-2023-4776

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first…

Fix: 2.2.5+
Fix from $1,950 2023-10-16
Wpschoolpress HIGH 8.8
CVE-2021-24575

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST v…

Fix: 2.1.10+
Fix from $1,950 2021-11-08