SQL Injection Vulnerability in WPSchoolPress Plugin for WordPress
CVE-2025-11981
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 November 2025
What is CVE-2025-11981?
The WPSchoolPress plugin for WordPress exhibits a vulnerability that allows SQL Injection through the 'SCodes' parameter. This flaw, found in all versions up to and including 2.2.23, arises from improper escaping of user-supplied data and inadequate preparation of SQL queries. As a result, authenticated attackers with administrator-level access can inject additional SQL commands into existing queries, potentially leading to unauthorized extraction of sensitive information from the database.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
School Management System – WPSchoolPress * <= 2.2.23
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved