The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is replicated across seven or more AJAX handlers including wlsm-fetch-staff-classes, wlsm-fetch-notices, wlsm-fetch-subjects, wlsm-fetch-inquiries, wlsm-fetch-staff-employee, and wlsm-fetch-payments, and the missing nonce verification on several of these handlers also enables CSRF-chained exploitation.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weblizar
Weblizar school Management - Education & Learning Management Wordpress Wordpress wordpress |
|
| Vendors & Products |
Weblizar
Weblizar school Management - Education & Learning Management Wordpress Wordpress wordpress |
Sun, 16 Aug 2026 05:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-08-16T05:27:31.050Z
Updated: 2026-08-17T19:28:52.922Z
Reserved: 2026-05-27T20:15:12.349Z
Link: CVE-2026-9767
Updated: 2026-08-17T19:28:08.630Z
Status : Received
Published: 2026-08-16T06:16:55.133
Modified: 2026-08-17T20:16:48.117
Link: CVE-2026-9767
No data.