The School Management plugin before version 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
id: CVE-2022-1609
info:
name: The School Management < 9.9.7 - Remote Code Execution
author: For
...