GradeBook

GradeBook has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; none of them are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.

None of the 2 issues recorded for GradeBook have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2023.

2 independent researchers contributed these findings, one record each. GradeBook is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage0%
Open

2

Fixed

0

Get automatic notifications for all GradeBook vulnerabilities before they are exploited.

Most severe open issueCVSS 8.8CVE-2023-2636

AN_GradeBook <= 5.0.1 - Authenticated (Subscriber+) SQL Injection via 'id'

Read the full analysis

Vulnerability Records

2 records
GradeBook banner
Latestv6.5.3
5.0(9)
100/100
Last Updated
2026-03-05 (6mo ago)
Active Installs
20+
Downloads
10,606
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2013-02-12 (14y ago)

GradeBook allows educators to manage courses, students, assignments, and grades directly from the WordPress dashboard. Instructor Features: Create, edit, and delete courses Add, edit, and remove students (new users or existing WordPress users) Create, edit, delete, and reorder assignments Edit grade cells inline Filter assignments by category and toggle visibility Sort by assignment columns Export gradebook data to CSV View student and assignment statistics with interactive charts Student Features: View enrolled courses and grades View assignment details including due dates View performance statistics with pie charts and line graphs Credits Plugin icon: IconFinder

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C