Impact
The School Management plugin for WordPress (mojoomla) contains an injection flaw that allows attackers to embed arbitrary SQL code through unsanitized inputs. This results in an SQL Injection (CWE‑89) that can enable unauthorized reading, modification, or deletion of database records, potentially exposing sensitive student data or compromising administrative credentials.
Affected Systems
All installations of the School Management plugin with a version equal to or lower than 92.0.0 are affected. The vulnerability is present in every pre‑92.0.0 release, regardless of the WordPress host or server environment, so any user running these versions faces the same risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score is below 1%, suggesting that real‑world exploitation is currently uncommon, and it is not listed in CISA's KEV catalog. Attackers would most likely exploit the flaw through HTTP inputs to the plugin’s endpoints; thus it is accessible over the network but may require authenticated access to the plugin’s administration interface.
OpenCVE Enrichment
EUVD