CVE-2024-12470

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 266

Summary

CVE-2024-12470 is a privilege escalation vulnerability affecting the School Management System plugin for WordPress, versions up to 1.0.8. The registration function in this plugin fails to enforce proper access control, allowing unauthenticated attackers to register as administrative users. Successful exploitation of this vulnerability could result in complete takeover of the WordPress site. To mitigate this risk, users are advised to update to the latest version of the plugin, implement strong access control policies, and regularly monitor for unauthorized user activity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share