๐Ÿ” CVE Alert

CVE-2024-9658

HIGH 8.8

School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email and password through the mj_smgt_update_user() and mj_smgt_add_admission() functions, along with a local file inclusion vulnerability. This makes it possible for authenticated attackers, with student-level access and above, to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account. This was escalated four months ago after no response to our initial outreach, yet it still vulnerable.

CWE CWE-288
Vendor dasinfomedia
Product school management system for wordpress
Published Mar 7, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for dasinfomedia school management system for wordpress

Be the first to know when new high vulnerabilities affecting dasinfomedia school management system for wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

dasinfomedia / School Management System for Wordpress
0 โ‰ค 93.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b5fd7bca-7754-4f83-8e51-5278e6e8cc78?source=cve codecanyon.net: https://codecanyon.net/item/school-management-system-for-wordpress/11470032

Credits

Tonn