Known CVE
The School Management < 9.9.7 - Remote Code Execution
The School Management plugin before version 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
CVE-2022-1609
Critical2022CVSS 9.8CWE-94
cve2022 · rce · wp · backdoor · wpscan · wordpress · weblizar · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website