What the vulnerability does
01Description
Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through <= 2.2.35.
Explanation of Vulnerability in Simple Terms
02Summary
WPSchoolPress versions up to 2.2.35 lack proper authorization checks, allowing high-privilege users to trigger a denial-of-service condition. An attacker with administrative or equivalent access can crash or disable the site's availability. The vulnerability does not affect data confidentiality or integrity. Update to version 2.2.36 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
Make the site unavailable or unresponsive by triggering a denial-of-service condition.
Potential impact on your site
04Site Impact
An admin or compromised high-privilege account can render your site unavailable without leaving a data breach.
Conditions required to exploit
05Prerequisites
Attacker must have high-privilege account access (e.g., administrator role) on the WordPress site.
Key dates
06Disclosure timeline
April 8, 2026
CVE published
April 29, 2026
Record updated