CVE-2025-1670
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 15, 2025
Updated: Mar 28, 2025
CWE ID 89
Summary
CVE-2025-1670 is a vulnerability affecting the WPSchoolPress plugin for WordPress. This issue, which exists in all versions up to 2.2.17, stems from insufficient escaping on the user-supplied 'cid' parameter and a lack of proper preparation of SQL queries. As a result, authenticated attackers with Custom-level access or higher can inject additional SQL queries into existing ones, potentially extracting sensitive data from the database.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.