Executive brief
The Attendance Manager plugin for WordPress, which is used to track and manage attendance records, contains a security flaw that allows logged-in users to interfere with the website's database. By exploiting this vulnerability, an attacker with even basic account access (such as a subscriber) could potentially steal sensitive information from the site's database. This could lead to the exposure of private user data or internal site configurations.
Technical details
The Attendance Manager plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'attmgr_off' parameter and a lack of SQL query preparation in the class-form.php file. This vulnerability affects all versions up to and including 0.6.2. An authenticated attacker with Subscriber-level permissions or higher can inject malicious SQL commands into existing queries. This can be leveraged to extract sensitive data from the WordPress database. The attack is carried out over the network and does not require user interaction beyond the attacker's own actions.
Affected products
- tnomi Attendance Manager 0.6.2 and all prior versions
Timeline
- 2026-04-08: disclosed: Initial disclosure by Wordfence and NVD publication.