Impact
The JoomSport plugin for WordPress contains a missing authorization check in the joomsport_season_groupdel AJAX handler, allowing a user with Subscriber-level access or higher to delete arbitrary group records by supplying a group ID; this results in loss of data associated with those groups and potentially disrupts league or team functions.
Affected Systems
The vulnerability affects beardev’s JoomSport plugin for Sports: Team & League, Football, Hockey & more, in all versions up to and including 5.7.8; any WordPress site using those plugin versions is impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the flaw requires only authentication with at least Subscriber privileges, with no special privileges needed. Because the EPSS score is not available, the likelihood of exploitation cannot be quantified, and the weakness is not listed in the CISA KEV catalog. Once authenticated, an attacker can repeatedly issue requests to the season_groupdel endpoint to delete any group record specified by the attacker, leading directly to data loss.
OpenCVE Enrichment