plugin

Wpschoolpress Vulnerabilities

31 known security issues reported for the Wpschoolpress WordPress plugin. Most recent disclosed Feb 13, 2026.

5 high 9 medium

Running Wpschoolpress on your site? Check whether your installed version is affected.

Scan your site free

WPSchoolPress <= 2.2.36 - Missing Authorization

medium

The WPSchoolPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.36. This makes it possible for authenticated attackers, with teacher-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.2.36
Fix:
No patched version reported
Disclosed:
Feb 13, 2026

CVE-2026-39631 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.2.24

unknown

[en] The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...

Affected:
up to 2.2.24
Fixed in:
2.2.24
Disclosed:
Nov 14, 2025

CVE-2025-11981 on NVD →

School Management System – WPSchoolPress <= 2.2.23 - Authenticated (Administrator+) SQL Injection

medium

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...

CVSS:
4.9
Affected:
up to 2.2.23
Fixed in:
2.2.24
Disclosed:
Nov 13, 2025

CVE-2025-11981 on NVD →

School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion

medium

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in all versions up to, and including, 2.2.16. This makes it possible for authenticated attackers, with teacher-level access and above, to delete...

CVSS:
4.3
Affected:
up to 2.2.16
Fixed in:
2.2.17
Disclosed:
Mar 14, 2025

CVE-2025-1668 on NVD →

School Management System – WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection

medium

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth...

CVSS:
6.5
Affected:
up to 2.2.16
Fixed in:
2.2.17
Disclosed:
Mar 14, 2025

CVE-2025-1670 on NVD →

School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Privilege Escalation via Account Takeover

high

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to, and including, 2.2.16. This makes it possible for authenticated attackers, with teacher-level access and above, to update...

CVSS:
8.8
Affected:
up to 2.2.16
Fixed in:
2.2.17
Disclosed:
Mar 14, 2025

CVE-2025-1667 on NVD →

School Management System – WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection

medium

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

CVSS:
6.5
Affected:
up to 2.2.17
Fixed in:
2.2.18
Disclosed:
Mar 14, 2025

CVE-2025-1669 on NVD →

School Management System – WPSchoolPress [wpschoolpress] <= 2.2.14 (unfixed)

unknown

[en] The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

Affected:
up to 2.2.14
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2024-12332 on NVD →

School Management System – WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection

medium

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth...

CVSS:
6.5
Affected:
up to 2.2.14
Fixed in:
2.2.15
Disclosed:
Jan 6, 2025

CVE-2024-12332 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.2.4

unknown

[en] Missing Authorization vulnerability in WPSchoolPress Team WPSchoolPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through 2.2.7.

Affected:
up to 2.2.4
Fixed in:
2.2.4
Disclosed:
Dec 13, 2024

CVE-2023-37887 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.2.11

unknown

[en] The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authe...

Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Oct 26, 2024

CVE-2024-9637 on NVD →

School Management System – WPSchoolPress <= 2.2.10 - Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation

high

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authentica...

CVSS:
8.8
Affected:
up to 2.2.10
Fixed in:
2.2.11
Disclosed:
Oct 25, 2024

CVE-2024-9637 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.2.5

unknown

[en] The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Oct 16, 2023

CVE-2023-4776 on NVD →

WPSchoolPress <= 2.2.4 - Authenticated(Teacher+) SQL Injection via ClassID

high

The WPSchoolPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘ClassID’ parameter in versions up to, and including, 2.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...

CVSS:
7.2
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Sep 25, 2023

CVE-2023-4776 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.2.5

unknown

Update the WordPress WPSchoolPress plugin to the latest available version (at least 2.2.5). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WPSchoolPress Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Sep 19, 2023

WPSchoolPress <= 2.2.4 - Cross-Site Request Forgery

medium

The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.4. This is due to missing nonce validation on several functions called via AJAX actions in the /lib/wpsp-ajaxworks.php file. This makes it possible for unauthenticated attackers to perform a multitud...

CVSS:
6.3
Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Sep 18, 2023

School Management System – WPSchoolPress [wpschoolpress] < 2.2.5

unknown

The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.4. This is due to missing nonce validation on several functions called via AJAX actions in the /lib/wpsp-ajaxworks.php file. This makes it possible for unauthenticated attackers to perform a multitud...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Sep 18, 2023

WPSchoolPress <= 2.2.3 - Missing Authorization

medium

The WPSchoolPress plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several functions such as wpsp_AddStudent(), wpsp_DeleteTeacher(), wpsp_UpdateStudent(), wpsp_DeleteStudent and more in versions up to, and including, 2.2.3. This makes it possible for authenti...

CVSS:
5.4
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Jul 11, 2023

CVE-2023-37887 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.1.17

unknown

[en] The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

Affected:
up to 2.1.17
Fixed in:
2.1.17
Disclosed:
Nov 8, 2021

CVE-2021-24664 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.1.10

unknown

[en] The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Nov 8, 2021

CVE-2021-24575 on NVD →

School Management System – WPSchoolPress <= 2.1.9 - SQL Injection

high

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to blind SQL Injection via the several parameters in versions up to, and including, 2.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
8.8
Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Oct 11, 2021

CVE-2021-24575 on NVD →

School Management System – WPSchoolPress < 2.1.10 - Reflected Cross-Site Scripting

high

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘entry_date’ parameter in versions before 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
7.1
Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Oct 11, 2021

School Management System – WPSchoolPress <= 2.1.16 - Stored Cross-Site Scripting

medium

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

CVSS:
4.8
Affected:
up to 2.1.17
Fixed in:
2.1.17
Disclosed:
Oct 11, 2021

CVE-2021-24664 on NVD →

School Management System – WPSchoolPress [wpschoolpress] < 2.1.10

unknown

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘entry_date’ parameter in versions before 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Oct 11, 2021

School Management System – WPSchoolPress [wpschoolpress] < 2.1.10

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WPSchoolPress plugin (versions <= 2.1.9).

Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Oct 11, 2021

School Management System – WPSchoolPress [wpschoolpress] < 2.1.10

unknown

The plugin does not escape user input before outputting back in some pages, leading to Reflected Cross-Site Scripting issues

Affected:
up to 2.1.10
Fixed in:
2.1.10

School Management System – WPSchoolPress [wpschoolpress] < 2.2.5

unknown

The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.4. This is due to missing nonce validation on several functions called via AJAX actions in the /lib/wpsp-ajaxworks.php file. This makes it possible for unauthenticated attackers to perform a multitud...

Affected:
up to 2.2.5
Fixed in:
2.2.5

School Management System – WPSchoolPress [wpschoolpress] <= 2.2.16 (unfixed)

unknown
Affected:
up to 2.2.16
Fix:
No patched version reported

CVE-2025-1669 on NVD →

School Management System – WPSchoolPress [wpschoolpress] <= 2.2.16 (unfixed)

unknown
Affected:
up to 2.2.16
Fix:
No patched version reported

CVE-2025-1667 on NVD →

School Management System – WPSchoolPress [wpschoolpress] <= 2.2.16 (unfixed)

unknown
Affected:
up to 2.2.16
Fix:
No patched version reported

CVE-2025-1670 on NVD →

School Management System – WPSchoolPress [wpschoolpress] <= 2.2.16 (unfixed)

unknown
Affected:
up to 2.2.16
Fix:
No patched version reported

CVE-2025-1668 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database