VYPR

School Management System

by WordPress

CVEs (2)

  • CVE-2023-4776HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

  • CVE-2024-13647MedFeb 27, 2025
    risk 0.28cvss 4.3epss 0.00

    The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the 'save_exam_setting' and 'delete_exam_setting' actions. This makes…