Junglewise Threat Intelligence

CVE-2026-39631: Ronik@UnlimitedWP WPSchoolPress missing authorization in access control

CVE-2026-39631 · Severity: medium · CVSS 4.9 · Published 2026-04-08

Executive brief

WPSchoolPress is a WordPress plugin used for school management, handling tasks like student records and attendance. A security flaw in the plugin's access control settings allows users with high-level permissions (such as teachers) to perform actions they should not be authorized to do. This could lead to unauthorized changes to school data or disruption of the management system.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the WPSchoolPress plugin for WordPress through version 2.2.35. The flaw is rooted in incorrectly configured access control security levels within the plugin's logic. A remote attacker with high-level privileges (such as a 'Teacher' role) can exploit this lack of authorization checks to perform actions beyond their intended scope. Depending on the specific implementation, this could result in a partial loss of availability or unauthorized data access. No official patch has been confirmed in the primary advisory, though users are advised to monitor for updates beyond version 2.2.35.

Affected products

  • Ronik@UnlimitedWP WPSchoolPress <= 2.2.35

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-13: advisory: Patchstack published initial advisory
  • 2026-04-08: disclosed: CVE-2026-39631 published

References