The School Management System – SakolaWP plugin for...
Critical severity
Unreviewed
Published
Jan 7, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jan 7, 2025
Published to the GitHub Advisory Database
Jan 7, 2025
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.
References