VendorsiGex Solutionswpschoolpressall versions
Vulnerabilities

iGex Solutions WPSchoolPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-24575
WPSchoolPress < 2.1.10 - Multiple Authenticated SQL Injections
Published 2021-11-08 · Modified
8.8EPSS 0.014
CVE-2023-4776
WPSchoolPress < 2.2.5 - Teacher+ SQLi
Published 2023-10-16 · Modified
8.8EPSS 0.007
CVE-2024-9637
School Management System – WPSchoolPress <= 2.2.10 - Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation
Published 2024-10-26 · Modified
8.8EPSS 0.005
CVE-2025-1667
School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Privilege Escalation via Account Takeover
Published 2025-03-15 · Modified
8.8EPSS 0.004
CVE-2024-12332
School Management System – WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection
Published 2025-01-07 · Modified
6.5EPSS 0.004
CVE-2025-1669
School Management System – WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection
Published 2025-03-15 · Modified
6.5EPSS 0.004
CVE-2025-1670
School Management System – WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection
Published 2025-03-15 · Modified
6.5EPSS 0.004
CVE-2025-1668
School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion
Published 2025-03-15 · Modified
5.4EPSS 0.003
CVE-2021-24664
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
Published 2021-11-08 · Modified
4.81 PoCEPSS 0.024