CVE-2022-1609 Scanner
Targets the plugin's admin-ajax.php endpoint; unauthenticated attackers can execute arbitrary PHP code to take over the WordPress site.
Used 2.4k times · 3.3k assets checked · domain, ipv4, subdomain
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
Targets the plugin's admin-ajax.php endpoint; unauthenticated attackers can execute arbitrary PHP code to take over the WordPress site.
Used 2.4k times · 3.3k assets checked · domain, ipv4, subdomain
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →