CVE-2025-49897: WordPress School Management Plugin <= 93.2.0 - Privilege Escalation Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blind SQL Injection. This issue affects Vertical scroll slideshow gallery v2: from n/a through 9.1.
Other sources
Incorrect Privilege Assignment vulnerability in gopiplus School Management school-management allows Privilege Escalation.This issue affects School Management: from n/a through <= 93.2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49897?
CVE-2025-49897 is classified as a high severity vulnerability due to the risk of Blind SQL Injection.
How do I fix CVE-2025-49897?
To fix CVE-2025-49897, update the gopiplus Vertical scroll slideshow gallery to the latest version beyond 9.1.
What versions are affected by CVE-2025-49897?
CVE-2025-49897 affects versions from 2.0 up to 9.1 of the gopiplus Vertical scroll slideshow gallery.
What type of vulnerability is CVE-2025-49897?
CVE-2025-49897 is an SQL Injection vulnerability, specifically a Blind SQL Injection issue.
Is CVE-2025-49897 specific to WordPress?
Yes, CVE-2025-49897 also affects the WordPress version of the Vertical scroll slideshow gallery up to version 9.1.