Wpschoolpress
Vendor:
First CVE: Nov 8, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 88% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wpschoolpress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
Mar 15, 2025
500 days ago
CVE Severity & Scoring
Wpschoolpress9 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low8 (88.9%)
High1 (11.1%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24664MEDIUM The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attribute | Nov 8, 2021 | 4.8 | 28 | NO | YES |
CVE-2021-24575HIGH The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading | Nov 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-4776HIGH The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to | Oct 16, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-9637HIGH The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is d | Oct 26, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-1670MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insuffi | Mar 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-1669MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.17 due to insu | Mar 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-12332MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insuffi | Jan 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-1668MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in al | Mar 15, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-1667MEDIUM The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in al | Mar 15, 2025 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Wpschoolpress
Top CWEs
Versions
No cataloged versions.