S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-1609

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
school-management-pro
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE-2022-1609 Scanner

Targets the plugin's admin-ajax.php endpoint; unauthenticated attackers can execute arbitrary PHP code to take over the WordPress site.

Used 2.4k times · 3.3k assets checked · domain, ipv4, subdomain

CVE history: school-management-pro

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →