Junglewise Threat Intelligence

CVE-2026-52712: Attendance Manager WordPress plugin SQL injection in Subscriber role

CVE-2026-52712 · Severity: high · CVSS 7.6 · Published 2026-06-16

Executive brief

Attendance Manager, a WordPress plugin used for tracking attendance, contains a security flaw that allows users with basic 'Subscriber' accounts to interfere with the site's database. By tricking an administrator into clicking a malicious link or visiting a specific page, an attacker can steal sensitive information or disrupt site operations. This vulnerability could be used in automated attacks to compromise website data.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Attendance Manager plugin for WordPress in versions up to and including 0.6.2. The flaw allows authenticated users with Subscriber-level privileges to execute arbitrary SQL commands via improperly neutralized input. Exploitation requires a degree of user interaction, such as a privileged user clicking a crafted link (reflected/UI-driven context). Successful exploitation can lead to unauthorized data extraction from the WordPress database. The issue is resolved in version 0.6.3.

Affected products

  • Attendance Manager Attendance Manager <= 0.6.2

Timeline

  • 2026-01-08: other: Reported by researcher daroo
  • 2026-06-15: advisory: Patchstack advisory published
  • 2026-06-16: disclosed: CVE published to NVD dataset

References