WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.4%
from disclosure to weapon7 days
Published on NVDNov 8
1st PoC+7d
exploitation probability
2.4%top 18% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.
Affected products
Unknown · School Management System – WPSchoolPresspublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/50520unverifiedcve_referencepacketstormsecurity.com/files/164974/WordPress-WPSchoolPress-2.1.16-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.