PT-2026-31098 · WordPress · Attendance Manager

Maurice Fielenbach

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-3781

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Attendance Manager plugin for WordPress versions up to and including 0.6.2
Description The Attendance Manager plugin for WordPress is susceptible to SQL Injection through the attmgr off parameter. This is a result of inadequate input sanitization and insufficient query preparation, potentially allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries and extract sensitive database information.
Recommendations Update the Attendance Manager plugin to a version newer than 0.6.2.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-3781

Affected Products

Attendance Manager