The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Jan 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user. | |
Title | School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-07T04:22:21.270Z
Updated: 2025-01-07T16:18:42.902Z
Reserved: 2024-12-10T22:35:37.459Z
Link: CVE-2024-12470
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-07T05:15:19.823
Modified: 2025-01-07T05:15:19.823
Link: CVE-2024-12470
Redhat
No data.