CVE-2026-52712 is a HIGH severity vulnerability (CVSS Score: 7.6) affecting Attendance Manager plugin versions <= 0.6.2. The vulnerability allows for Subscriber SQL Injection attacks, potentially enabling attackers to manipulate database queries. The vulnerability was published on [cvePublishedAt] and has not been modified since.
The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all versions up to, and including, 0.6.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This vulnerability allows authenticated attackers with Subscriber-level access and above to append additional SQL queries into [truncated]