A vulnerability has been found in Weblizar The School Management Plugin up to 5.4 on WordPress and classified as critical. This affects an unknown part of the component AJAX handlers. Performing a manipulation of the argument order[0][dir] results in sql injection.
This vulnerability is reported as CVE-2026-9767. The attack is possible to be carried out remotely. No exploit exists.