Igexsolutions
Igexsolutions Wpschoolpress: vulnerabilidades y CVE
Igexsolutions Wpschoolpress tiene 12 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-39631 | Media (4.9) | 0.40% | — | 8 abr 2026 | Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through <= 2.2.35. |
| CVE-2025-11981 | Media (4.9) | 0.31% | — | 14 nov 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied… |
| CVE-2025-1670 | Media (6.5) | 0.38% | — | 15 mar 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.16 due to insufficient escaping on the user supplied… |
| CVE-2025-1669 | Media (6.5) | 0.38% | — | 15 mar 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, 2.2.17 due to insufficient escaping on the user supplied… |
| CVE-2025-1668 | Media (5.4) | 0.30% | — | 15 mar 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function in all versions up to, and including,… |
| CVE-2025-1667 | Media (4.3) | 0.36% | — | 15 mar 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to, and including,… |
| CVE-2024-12332 | Media (6.5) | 0.43% | — | 7 ene 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied… |
| CVE-2023-37887 | Media (6.5) | 0.60% | — | 13 dic 2024 | Missing Authorization vulnerability in WPSchoolPress Team WPSchoolPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through 2.2.7. |
| CVE-2024-9637 | Alta (8.8) | 0.48% | — | 26 oct 2024 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly… |
| CVE-2023-4776 | Alta (8.8) | 0.72% | — | 16 oct 2023 | The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by… |
| CVE-2021-24664 | Media (4.8) | 2.4% | — | 8 nov 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site… |
| CVE-2021-24575 | Alta (8.8) | 1.4% | — | 8 nov 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.