Description
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50882 | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user. |
References
History
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jan 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user. | |
| Title | School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-07T16:18:42.902Z
Reserved: 2024-12-10T22:35:37.459Z
Link: CVE-2024-12470
Updated: 2025-01-07T15:57:04.975Z
Status : Received
Published: 2025-01-07T05:15:19.823
Modified: 2025-01-07T05:15:19.823
Link: CVE-2024-12470
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD