CVE-2024-12470
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-12470 is a privilege escalation vulnerability affecting the School Management System plugin for WordPress, versions up to 1.0.8. The registration function in this plugin fails to enforce proper access control, allowing unauthenticated attackers to register as administrative users. Successful exploitation of this vulnerability could result in complete takeover of the WordPress site. To mitigate this risk, users are advised to update to the latest version of the plugin, implement strong access control policies, and regularly monitor for unauthorized user activity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress