School Management System for Wordpress

Information

Software Type Plugin
Software Slug school-management
Software Status Active
Software Author dasinfomedia
Software Website codecanyon.net
Software Active Installs 1,844
Software Record Last Updated March 16, 2026

Showing 1-20 of 21 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection Unpatched CVE-2024-12612 7.5 Lucio Sá August 15, 2025
School Management System <= 93.2.0 - Authenticated (Student+) Arbitrary File Upload Unpatched CVE-2025-6079 8.8 Foxyyy August 15, 2025
School Management <= 93.2.0 - Authenticated (Support staff+) SQL Injection Unpatched CVE-2025-49898 6.5 Thái An August 15, 2025
School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference Unpatched CVE-2025-49896 5.3 Tran Nguyen Bao Khanh August 15, 2025
School Management <= 93.2.0 - Missing Authorization Unpatched CVE-2025-48108 4.3 Nguyen Kim Sang August 15, 2025
School Management <= 1.93.1 (02-07-2025) - Authenticated (Student+) Arbitrary File Upload Unpatched CVE-2025-31100 9.8 Bonds August 12, 2025
School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update Patched CVE-2025-3740 8.8 Thái An July 17, 2025
School Management <= 92.0.0 - Reflected Cross-Site Scripting Unpatched CVE-2025-47574 6.1 Bonds June 18, 2025
School Management <= 93.0.0 - Authenticated (Student+) Local File Inclusion Unpatched CVE-2025-47572 8.8 Annn June 12, 2025
School Management <= 92.0.0 - Unauthenticated SQL Injection Unpatched CVE-2025-47573 7.5 Bonds June 11, 2025
School Management <= 92.0.0 - Reflected Cross-Site Scripting Unpatched CVE-2025-47613 6.1 Trương Hữu Phúc (truonghuuphuc) May 20, 2025
School Management <= 92.0.0 - Authenticated (Subscriber+) SQL Injection Unpatched CVE-2025-47575 6.5 Cút lộn xào me May 20, 2025
School Management System for Wordpress <= 92.0.0 - Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' Patched CVE-2024-12607 6.5 shaman0x01 March 6, 2025
School Management System for Wordpress <= 92.0.0 - Authenticated (Student+) SQL Injection via 'view-attendance' Patched CVE-2024-12609 6.5 shaman0x01 March 6, 2025
School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion Unpatched CVE-2024-12610 5.3 Lucio Sá March 6, 2025
School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting Unpatched CVE-2024-12611 5.3 Lucio Sá March 6, 2025
School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation Unpatched CVE-2024-9658 8.8 Tonn March 6, 2025
School Management <= 91.5.0 - Authenticated (Student+) Arbitrary File Upload Patched CVE-2024-9660 8.8 Tonn November 22, 2024
School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload Patched CVE-2024-9659 9.8 Tonn November 22, 2024
School Management System for Wordpress <= 56.0 - Cross-Site Request Forgery Patched 8.8 m0ns7er July 13, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation