Description
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode.
Published: 2026-07-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check on the season_groupedit AJAX endpoint in the JoomSport WordPress plugin enables any authenticated user who has a subscriber role or higher to create new season groups or alter the name, participants, and round‑type options of existing groups. This flaw, identified as CWE‑862, permits them to do so, effectively allowing unauthorized control over the season structure.

Affected Systems

All installations of beardev:JoomSport – for Sports: Team & League, Football, Hockey & more running version 5.7.8 or earlier are affected. WordPress sites that load the plugin, regardless of theme or additional plugins, are at risk, as the vulnerability can be triggered on any page that renders a JoomSport shortcode.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity assessment. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. No versions of the vulnerability are listed in the CISA KEV catalog. Exploitation requires an authenticated attacker who has obtained the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode, making this a local, authenticated vulnerability that can be triggered on the affected WordPress site.

Generated by OpenCVE AI on July 21, 2026 at 12:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JoomSport plugin to a version newer than 5.7.8 that enforces proper authorization checks on the season_groupedit AJAX endpoint.
  • Implement explicit role checks before processing any AJAX request that modifies season group data, ensuring only users with managerial or administrative privileges can perform these actions.
  • Restrict the rendering of the joomsportajaxnonce to pages that are accessible only to users with sufficient privileges, thereby preventing exposure to public or low‑privilege users.
  • Audit existing season groups for evidence of unauthorized entries or modifications and, if necessary, restore them to known correct states from backups.

Generated by OpenCVE AI on July 21, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Beardev
Beardev joomsport – For Sports: Team & League, Football, Hockey & More
Wordpress
Wordpress wordpress
Vendors & Products Beardev
Beardev joomsport – For Sports: Team & League, Football, Hockey & More
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Description The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode.
Title JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Beardev Joomsport – For Sports: Team & League, Football, Hockey & More
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-02T14:57:35.251Z

Reserved: 2026-06-12T15:33:51.321Z

Link: CVE-2026-12134

cve-icon Vulnrichment

Updated: 2026-07-02T14:57:31.310Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:30:03Z

Weaknesses