← WordPress Vulnerabilities
WordPress security by component

CoSchool LMS

CoSchool LMS is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Nov 06, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: coschool

CVE-2025-60239: CoSchool LMS: SQL injection

CoSchool LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

PublishedNov 06, 2025
Safe version guidanceSee mitigation notes
Safe version
Nov 06, 2025 CVE-2025-60239
CoSchool LMS: SQL injection
CoSchool LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Jul 16, 2025 CVE-2025-30973
CoSchool LMS: Code execution
CoSchool LMS is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Dec 13, 2024 CVE-2024-54296
CoSchool LMS: Privilege escalation or authentication bypass
CoSchool LMS is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending