CVE-2024-12470: School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation

9.8 CVSS

Description

The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.

Classification

CVE ID: CVE-2024-12470

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

Affected Products

Vendor: themesawesome

Product: School Management System – SakolaWP

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.09% (probability of being exploited)

EPSS Percentile: 40.74% (scored less or equal to compared to others)

EPSS Date: 2025-02-05 (when was this score calculated)

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/db1c581b-5cc9-46c0-ba5d-605642697729?source=cve
https://wordpress.org/plugins/sakolawp-lite/

Timeline