Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection.

This issue affects School Management: from n/a through 93.2.0.
Published: 2026-06-03
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A failure to properly neutralize special elements in an SQL command introduces a classic SQL injection flaw (CWE‑89). An attacker can craft inputs that are concatenated into backend queries, potentially enabling unauthorized data disclosure, modification, or removal. The vulnerability resides in the School Management plugin on WordPress, which accepts user‑supplied parameters without adequate sanitization. The impact is limited to the WordPress installation where the plugin is active, but data compromise could be extensive if the database contains sensitive student records or administrative credentials. The flaw exists in the Mojoomla School Management plugin for WordPress for all released versions up to and including 93.2.0. The vendor product is Mojoomla School Management, and impacted installations are those running this plugin on any WordPress site without an earlier update. No specific operating system requirement is noted; the vulnerability is tied to the PHP code executed within the WordPress environment. The CVSS score of 7.6 indicates a high severity, reflecting a significant impact and a relatively high exploitation difficulty. The EPSS score is not available, so no current estimate of exploit popularity can be quoted. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely observed in the wild. The likely attack vector is local or remote if the plugin accepts input from unauthenticated users, which would allow an attacker to send specially crafted requests directly to the WordPress site and execute arbitrary SQL statements against the database.

Affected Systems

Mojoomla School Management plugin for WordPress versions up to and including 93.2.0.

Risk and Exploitability

The CVSS score of 7.6 signals high severity and a relatively high exploitation difficulty. EPSS is not available; KEV status is not listed, implying no confirmed widespread exploitation. The likely attack vector is local or remote, contingent on the plugin accepting input from unauthenticated users, permitting an attacker to transmit malicious SQL via crafted requests.

Generated by OpenCVE AI on June 3, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch for the School Management plugin (version 93.3.0 or later).
  • If the patch is temporarily unavailable, disable the plugin until it can be updated.
  • Restrict the database user privileges to read‑only for the WordPress account to minimize damage from leaked or injected queries.
  • Deploy a web application firewall rule that detects and blocks suspicious SQL injection patterns targeting the plugin’s input fields.

Generated by OpenCVE AI on June 3, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mojoomla
Mojoomla school Management
Wordpress
Wordpress wordpress
Vendors & Products Mojoomla
Mojoomla school Management
Wordpress
Wordpress wordpress

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.
Title WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Mojoomla School Management
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-03T12:35:57.420Z

Reserved: 2026-06-03T08:56:48.454Z

Link: CVE-2025-15655

cve-icon Vulnrichment

Updated: 2026-06-03T12:35:51.820Z

cve-icon NVD

Status : Received

Published: 2026-06-03T11:16:19.250

Modified: 2026-06-03T11:16:19.250

Link: CVE-2025-15655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T13:30:25Z

Weaknesses