← Back to browse · API

CVE-2022-1609

Severity
CRITICAL
CVSS
9.8
EPSS
0.64321
Risk score
61.71
CISA KEV
No
PoC
No
Published
2024-01-16
Modified
2025-06-02
First seen
2026-08-07
Aliases
EUVD-2022-24898, GHSA-4G99-5GW9-42HV
Products
Unknown:school-management-pro 0 <9.9.7
Sources
euvd EUVD-2022-24898

Description

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

References