Junglewise Threat Intelligence

CVE-2025-15655: Mojoomla School Management SQL injection

CVE-2025-15655 · Severity: high · CVSS 7.6 · Published 2026-06-03

Technologies: Mojoomla School Management. Vendors: Mojoomla.

Executive brief

The School Management plugin for WordPress, used to manage educational administrative tasks, contains a security flaw that could allow an attacker to interfere with the website's database. By exploiting this vulnerability, a malicious actor could potentially steal sensitive student or staff information, modify records, or disrupt school operations. This issue affects all versions up to 93.2.0, and no official patch has been released yet.

Technical details

An SQL injection vulnerability exists in the Mojoomla School Management plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw affects versions up to and including 93.2.0. An attacker with 'Support Staff' or higher privileges can exploit this vulnerability to perform unauthorized queries against the underlying database. This could lead to the exfiltration of sensitive data, modification of database records, or full administrative bypass. As of the advisory date, no official patch is available, and users are advised to monitor for updates or implement web application firewall (WAF) rules to mitigate the risk.

Affected products

  • Mojoomla School Management <= 93.2.0

Timeline

  • 2025-05-18: other: Reported by researcher Aiden
  • 2025-08-15: advisory: Early warning and publication by Patchstack
  • 2026-06-03: disclosed: NVD publication date

References

Related threats