SQL Injection Vulnerability in WPSchoolPress Plugin for WordPress
CVE-2025-11981
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 November 2025
What is CVE-2025-11981?
The WPSchoolPress plugin for WordPress exhibits a vulnerability that allows SQL Injection through the 'SCodes' parameter. This flaw, found in all versions up to and including 2.2.23, arises from improper escaping of user-supplied data and inadequate preparation of SQL queries. As a result, authenticated attackers with administrator-level access can inject additional SQL commands into existing queries, potentially leading to unauthorized extraction of sensitive information from the database.
Affected Version(s)
School Management System – WPSchoolPress * <= 2.2.23