Impact
WordPress WPSchoolPress plugin versions up to 2.2.35 contain a missing authorization flaw that allows attackers to perform actions beyond their intended permissions. This broken access control can enable unauthorized modification or deletion of school data normally restricted to administrators. The weakness is classified as CWE‑862, indicating a lack of proper access control checks.
Affected Systems
The vulnerability affects the Ronik@UnlimitedWP WPSchoolPress plugin, a WordPress plugin used to manage school content. All installations running version 2.2.35 or earlier are impacted. The plugin is available from the WordPress plugin repository and can be installed on any WordPress site that hosts school or educational content.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate impact, and the EPSS score of less than 1% suggests that it is unlikely to be exploited in the wild. It is not listed in the CISA known exploited vulnerabilities catalog. The likely attack vector is remote access to plugin endpoints lacking proper permission checks, inferred from the missing authorization description, though explicit exploitation details are not provided in the advisory.
OpenCVE Enrichment