CVE-2022-1609
The School Management < 9.9.7 - Unauthenticated RCE via REST api
- Published
- Jan 16, 2024
- Updated
- Jun 2, 2025
- Assigning CNA
- WPScan
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.2%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
Sources
3Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor
Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor
- CVE-2022-1609Exploit
CVE-2022-1609 WordPress Weblizar后门
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.