WordPress · School Management – Education & Learning Erp · CVE-2026-9767
**Name of the Vulnerable Software and Affected Versions**
The School Management – Education & Learning ERP plugin for WordPress versions prior to 5.5
**Description**
Authenticated attackers with custom-level access and above can perform SQL Injection by appending additional queries to existing ones to extract sensitive database information. This occurs due to insufficient escaping of user-supplied parameters and lack of proper preparation of SQL queries. The issue affects the `order[0][dir]` parameter across seven or more AJAX handlers, including `wlsm-fetch-staff-classes`, `wlsm-fetch-notices`, `wlsm-fetch-subjects`, `wlsm-fetch-inquiries`, `wlsm-fetch-staff-employee`, and `wlsm-fetch-payments`. Additionally, the absence of nonce verification—a security token used to prevent Cross-Site Request Forgery (CSRF)—on several of these handlers allows for CSRF-chained exploitation.
**Recommendations**
Update the School Management – Education & Learning ERP plugin for WordPress to a version newer than 5.4.