CVE-2024-12470 | School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrative user.
Conclusion & alert: CVE-2024-12470 is rated Moderate Risk (62.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.52%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2024-12470
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).