CVE-2025-3740 | School Management System Plugin up to 1.93.1/93.1.0 on WordPress Password Update page file inclusion
A vulnerability, which was classified as problematic, was found in School Management System Plugin up to 1.93.1/93.1.0 on WordPress. This affects an unknown part of the component Password Update Handler. The manipulation of the argument page leads to file inclusion.
This vulnerability is uniquely identified as CVE-2025-3740. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.