Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-03-21

CVE-2024-13647 - Sakolawp Plugin

The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the 'save_exam_setting' and 'delete_exam_setting' actions. This makes it possible for unauthenticated attackers to update exam settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Sakolawp

CVE-2024-13647

MEDIUM CVSS 4.3 2025-02-27
Threat Entry Updated 2025-01-07

CVE-2024-12470 - Sakolawp Plugin

The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.

PLUGIN Sakolawp

CVE-2024-12470

CRITICAL CVSS 9.8 2025-01-07
Scroll to top