SQL Injection Vulnerability in School Management System for WordPress
CVE-2024-12607
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2025
What is CVE-2024-12607?
The School Management System plugin for WordPress contains a SQL injection vulnerability through the 'id' parameter in the 'mj_smgt_show_event_task' AJAX action. This issue arises due to inadequate escaping of user input and insufficient preparation of SQL queries. As a result, authenticated attackers with Custom-level access can manipulate existing SQL queries, potentially enabling them to extract sensitive data from the database.
Affected Version(s)
School Management System for Wordpress * <= 92.0.0