Arbitrary User Deletion Vulnerability in WPSchoolPress Plugin for WordPress
CVE-2025-1668
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 March 2025
What is CVE-2025-1668?
The WPSchoolPress plugin for WordPress is susceptible to an arbitrary user deletion vulnerability due to an oversight in the wpsp_DeleteUser() function. This flaw allows authenticated users with teacher-level permissions and above to delete any user account without appropriate checks in place. This vulnerability is present in all versions up to and including version 2.2.16, posing a significant risk to user data integrity within school management systems.
Affected Version(s)
School Management System – WPSchoolPress * <= 2.2.16