WordPress School Management Plugin <= 1.93.1 (02-07-2025) - Arbitrary File Upload Vulnerability
School Management
Minimum safe version
93.0.0
Update to 93.0.0 or later to address 8 fixable vulnerabilities
WordPress School Management Plugin <= 93.2.0 - Broken Access Control Vulnerability
School Management <= 93.2.0 - Missing Authorization
School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference
School Management <= 93.2.0 - Authenticated (Support staff+) SQL Injection
School Management System <= 93.2.0 - Authenticated (Student+) Arbitrary File Upload
School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection
School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update
WordPress School Management System Plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress School Management <= 93.0.0 - Local File Inclusion Vulnerability
WordPress School Management System Plugin <= 92.0.0 - SQL Injection vulnerability
WordPress School Management plugin <= 92.0.0 - SQL Injection vulnerability
WordPress School Management System for Wordpress plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation
School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting
CVE-2024-12607
School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
CVE-2024-12609
CVE-2024-9660
CVE-2024-9659
School Management < 57.0 - CSRF and Stored XSS
School Management System for Wordpress <= 56.0 - Cross-Site Request Forgery
WordPress School Management plugin < 57.0 - Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities