Igexsolutions maintains a narrowly scoped product portfolio centered on WPSchoolPress, a WordPress-based school management platform deployed in educational environments. The vendor's vulnerability profile is characterized by recurring application-layer input-handling and authorization weaknesses—SQL injection, cross-site scripting, authorization bypass, and missing authorization checks—which are typical of web-facing administrative platforms, and these disclosures frequently acquire public exploit code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Igexsolutions over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24664MEDIUM The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attribute | Nov 8, 2021 | 4.8 | 28 | NO | YES |
CVE-2021-24575HIGH The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading | Nov 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-4776HIGH The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to | Oct 16, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-9637HIGH The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is d | Oct 26, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-1670MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insuffi | Mar 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-1669MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.17 due to insu | Mar 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-12332MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insuffi | Jan 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-1668MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in al | Mar 15, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-1667MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in al | Mar 15, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Igexsolutions.
Media articles that mention a CVE ID that affects a product developed by Igexsolutions — matched by CVE ID, not by vendor name.