Junglewise Threat Intelligence

CVE-2025-15656: Mojoomla School Management privilege escalation in WordPress plugin

CVE-2025-15656 · Severity: high · CVSS 8.8 · Published 2026-06-03

Technologies: Mojoomla School Management. Vendors: Mojoomla.

Executive brief

A vulnerability in the Mojoomla School Management plugin for WordPress allows users with low-level access to gain administrative control. This plugin is used by educational institutions to manage student data, staff, and school operations. An attacker could exploit this flaw to access sensitive student records, modify school data, or take over the entire website.

Technical details

The Mojoomla School Management plugin for WordPress (versions up to and including 93.2.0) contains an incorrect privilege assignment vulnerability. This flaw allows an authenticated attacker with low-level permissions (such as Support Staff) to escalate their privileges to a higher level, potentially gaining full administrative access to the WordPress site. The vulnerability is classified under OWASP A5: Security Misconfiguration. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.

Affected products

  • Mojoomla School Management <= 93.2.0

Timeline

  • 2025-05-18: other: Vulnerability reported by researcher
  • 2025-06-17: disclosed: Public disclosure by Patchstack
  • 2026-06-03: advisory: NVD publication date

References