Input validation vulnerability in School Management System – WPSchoolPress 2.2.16

The School Management System – WPSchoolPress plugin for WordPress has a security issue where an attacker can inject harmful code through a specific parameter called ‘cid’. This can happen in all versions up to 2.2.16. It is caused by not properly handling the user’s input and not preparing the existing code well enough. This means that someone with access to the system and higher privileges can add their own code to the existing code and potentially access sensitive information from the database.

Detected in:

School Management System – WPSchoolPress open vulnerable versions: >= * <= 2.2.16

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.