SQL Injection Vulnerability in School Management ERP Plugin for WordPress
CVE-2026-9767
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-9767?
The School Management β Education & Learning ERP plugin for WordPress is susceptible to SQL Injection vulnerabilities through the 'order[0][dir]' parameter due to insufficient parameter escaping and inadequate preparation of SQL queries. This vulnerability permits authenticated attackers with custom-level access or higher to inject malicious SQL code alongside existing queries, facilitating unauthorized access to sensitive database information. The flaw extends to multiple AJAX handlers such as wlsm-fetch-staff-classes and wlsm-fetch-payments, and the absence of nonce verification on several handlers potentially allows for CSRF-chained attacks.
Affected Version(s)
The School Management β Education & Learning ERP 0 <= 5.4