SQL Injection Vulnerability in School Management ERP Plugin for WordPress
CVE-2026-9767

6.5MEDIUM

What is CVE-2026-9767?

The School Management – Education & Learning ERP plugin for WordPress is susceptible to SQL Injection vulnerabilities through the 'order[0][dir]' parameter due to insufficient parameter escaping and inadequate preparation of SQL queries. This vulnerability permits authenticated attackers with custom-level access or higher to inject malicious SQL code alongside existing queries, facilitating unauthorized access to sensitive database information. The flaw extends to multiple AJAX handlers such as wlsm-fetch-staff-classes and wlsm-fetch-payments, and the absence of nonce verification on several handlers potentially allows for CSRF-chained attacks.

Affected Version(s)

The School Management – Education & Learning ERP 0 <= 5.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

j4ck13ch4n
.