Critical severity9.8NVD Advisory· Published Jan 16, 2024· Updated Jun 17, 2026
CVE-2022-1609
CVE-2022-1609
Description
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:weblizar:school_management:*:*:*:*:pro:wordpress:*:*Range: <9.9.7
<9.9.7+ 1 more
- (no CPE)range: <9.9.7
- (no CPE)
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/e2d546c9-85b6-47a4-b951-781b9ae5d0f2/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.