Executive brief
The School Management plugin for WordPress, which is used to manage educational administrative tasks, contains a security flaw that allows unauthorized access to certain data. An attacker can exploit this vulnerability to view information they should not have access to by manipulating identifiers in web requests. This could lead to the exposure of sensitive school-related records or student information without requiring a login.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Mojoomla School Management plugin for WordPress in versions up to and including 93.1.0. The flaw stems from insufficient authorization checks when accessing specific objects or records via user-controlled input. An unauthenticated remote attacker can exploit this by modifying parameters in requests to access sensitive information or interact with data they are not authorized to view. As of the advisory date, no official patch has been released, and the vulnerability is classified as having a medium severity with a CVSS score of 5.3.
Affected products
- Mojoomla School Management <= 93.1.0
Timeline
- 2025-05-18: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2025-08-15: advisory: Published by Patchstack
- 2026-06-17: disclosed: NVD Published Date