Executive brief
Attendance Manager, a WordPress plugin used for tracking attendance, contains a security flaw that allows users with basic 'Subscriber' accounts to interfere with the site's database. By tricking an administrator into clicking a malicious link or visiting a specific page, an attacker can steal sensitive information or disrupt site operations. This vulnerability could be used in automated attacks to compromise website data.
Technical details
A SQL injection vulnerability (CWE-89) exists in the Attendance Manager plugin for WordPress in versions up to and including 0.6.2. The flaw allows authenticated users with Subscriber-level privileges to execute arbitrary SQL commands via improperly neutralized input. Exploitation requires a degree of user interaction, such as a privileged user clicking a crafted link (reflected/UI-driven context). Successful exploitation can lead to unauthorized data extraction from the WordPress database. The issue is resolved in version 0.6.3.
Affected products
- Attendance Manager Attendance Manager <= 0.6.2
Timeline
- 2026-01-08: other: Reported by researcher daroo
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-16: disclosed: CVE published to NVD dataset