PT-2025-1859 · WordPress · Sakolawp

Thanh Nam Tran

·

Published

2025-01-07

·

Updated

2025-01-12

·

CVE-2024-12470

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Management System – SakolaWP plugin for WordPress versions up to and including 1.0.8
Description The issue is due to the registration function not properly limiting what roles a user can register as, making it possible for unauthenticated attackers to register as an administrative user. This allows attackers to escalate privileges.
Recommendations For versions up to and including 1.0.8, update to version 1.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the registration function until the update is applied.

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12470

Affected Products

Sakolawp