CVE-2025-1667

Published Mar 15, 2025

Last updated 7 days ago

Overview

Description
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to, and including, 2.2.16. This makes it possible for authenticated attackers, with teacher-level access and above, to update arbitrary user details including email which makes it possible to request a password reset and access arbitrary user accounts, including administrators.
Source
security@wordfence.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

security@wordfence.com
CWE-639
nvd@nist.gov
CWE-862

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-1667 🔴 HIGH (8.8) 🏢 jdsofttech - School Management System – WPSchoolPress 🏗️ * 🔗 https://t.co/V7YGctCn9Y 🔗 https://t.co/oGPdwf5fVP #CyberCron #VulnAlert #InfoSec https://t.co/SOLHgZFyBr

    @cybercronai

    15 Mar 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. New post from https://t.co/uXvPWJy6tj (CVE-2025-1667 | jdsofttech School Management System Plugin up to 2.2.16 on WordPress Password Reset wpsp_UpdateTeacher authorization) has been published on https://t.co/ua2gLMpWfg

    @WolfgangSesin

    15 Mar 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. �� CVE-2025-1667 - WordPress - HIGH 🚨 🗓️ Date published 2025-03-15 04:15:21 UTC #WordPress #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/wRPyeEkgLw

    @vulns_space

    15 Mar 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. [CVE-2025-1667: HIGH] WordPress plugin WPSchoolPress (up to v2.2.16) is vulnerable to Privilege Escalation due to missing capability check on wpsp_UpdateTeacher() function. Authenticated attackers can update user ...#cybersecurity,#vulnerability https://t.co/zBjjRCQXdh https://t.

    @CveFindCom

    15 Mar 2025

    38 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-1667 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() fu… https://t.co/g5ZSP87iUf

    @CVEnew

    15 Mar 2025

    506 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations