CVE-2025-15657 is a MEDIUM severity vulnerability (CVSS Score: 5.3) affecting School Management plugin versions <= 93.1.0. This Unauthenticated Insecure Direct Object References (IDOR) vulnerability allows attackers to access sensitive data without authentication. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected plugin should take immediate action [truncated]
The CVE record for CVE-2026-39433 was published on 2026-06-17T13:20:18.053Z and is currently marked as Deferred in the NVD. This MEDIUM severity vulnerability affects the WPAMS plugin, allowing subscribers to delete arbitrary content. The vulnerability has a CVSS score of 6.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Users of WPAMS plugin versions prior to 49.5.3 are advised to re [truncated]