CVE-2026-39631
School Management System – WPSchoolPress
Minimum safe version
2.2.24
Update to 2.2.24 or later to address 17 fixable vulnerabilities
CVE-2025-11981
School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion
School Management System – WPSchoolPress <= 2.2.16 - Authenticated (Parent+) SQL Injection
School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Privilege Escalation via Account Takeover
School Management System – WPSchoolPress <= 2.2.17 - Authenticated (Teacher+) SQL Injection
CVE-2024-12332
CVE-2024-9637
WPSchoolPress < 2.2.5 - Cross-Site Request Forgery
WordPress WPSchoolPress Plugin < 2.2.5 is vulnerable to SQL Injection
WordPress WPSchoolPress Plugin < 2.2.5 is vulnerable to Cross Site Request Forgery (CSRF)
WPSchoolPress <= 2.2.4 - Cross-Site Request Forgery
CVE-2023-37887
WPSchoolPress < 2.1.10 - Reflected Cross-Site Scripting
School Management System – WPSchoolPress < 2.1.10 - Reflected Cross-Site Scripting
WordPress WPSchoolPress plugin <= 2.1.9 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2021-24664
CVE-2021-24575