Extension WordPress
Vulnérabilités School Management System – WPSchoolPress
Cette page rassemble les failles publiées pour School Management System – WPSchoolPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de School Management System – WPSchoolPress
14 fiches
WPSchoolPress <= 2.2.36 – Missing Authorization
The WPSchoolPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.36. This makes it possible for authenticated attackers, with teacher-level access and above,…
*-2.2.36
Non indiqué
13/02/2026
School Management System – WPSchoolPress <= 2.2.23 – Authenticated (Administrator+) SQL Injection
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of…
*-2.2.23
2.2.24
13/11/2025
School Management System – WPSchoolPress <= 2.2.16 – Missing Authorization to Arbitrary User Deletion
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in all versions up to, and including, 2.2.16. This makes it possible for…
*-2.2.16
2.2.17
14/03/2025
School Management System – WPSchoolPress <= 2.2.16 – Authenticated (Parent+) SQL Injection
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insufficient escaping on the user supplied parameter and lack of…
*-2.2.16
2.2.17
14/03/2025
School Management System – WPSchoolPress <= 2.2.16 – Missing Authorization to Privilege Escalation via Account Takeover
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to, and including, 2.2.16. This makes it possible for authenticated…
*-2.2.16
2.2.17
14/03/2025
School Management System – WPSchoolPress <= 2.2.17 – Authenticated (Teacher+) SQL Injection
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.17 due to insufficient escaping on the user supplied parameter and lack of…
*-2.2.17
2.2.18
14/03/2025
School Management System – WPSchoolPress <= 2.2.14 – Authenticated (Student/Parent+) SQL Injection
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of…
*-2.2.14
2.2.15
06/01/2025
School Management System – WPSchoolPress <= 2.2.10 – Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior…
*-2.2.10
2.2.11
25/10/2024
WPSchoolPress <= 2.2.4 – Authenticated(Teacher+) SQL Injection via ClassID
The WPSchoolPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘ClassID’ parameter in versions up to, and including, 2.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-2.2.4
2.2.5
25/09/2023
WPSchoolPress <= 2.2.4 – Cross-Site Request Forgery
The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.4. This is due to missing nonce validation on several functions called via AJAX actions in the /lib/wpsp-ajaxworks.php file. This makes…
[*, 2.2.5)
2.2.5
18/09/2023
WPSchoolPress <= 2.2.3 – Missing Authorization
The WPSchoolPress plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several functions such as wpsp_AddStudent(), wpsp_DeleteTeacher(), wpsp_UpdateStudent(), wpsp_DeleteStudent and more in versions up to, and including, 2.2.3. This makes…
*-2.2.3
2.2.4
11/07/2023
School Management System – WPSchoolPress <= 2.1.16 – Stored Cross-Site Scripting
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.
[*, 2.1.17)
2.1.17
11/10/2021
School Management System – WPSchoolPress <= 2.1.9 – SQL Injection
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to blind SQL Injection via the several parameters in versions up to, and including, 2.1.9 due to insufficient escaping on the user supplied parameter and lack of…
[*, 2.1.10)
2.1.10
11/10/2021
School Management System – WPSchoolPress < 2.1.10 – Reflected Cross-Site Scripting
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘entry_date’ parameter in versions before 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 2.1.10)
2.1.10
11/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.