Impact
A missing authorization check on the season_groupedit AJAX endpoint in the JoomSport WordPress plugin enables any authenticated user who has a subscriber role or higher to create new season groups or alter the name, participants, and round‑type options of existing groups. This flaw, identified as CWE‑862, permits them to do so, effectively allowing unauthorized control over the season structure.
Affected Systems
All installations of beardev:JoomSport – for Sports: Team & League, Football, Hockey & more running version 5.7.8 or earlier are affected. WordPress sites that load the plugin, regardless of theme or additional plugins, are at risk, as the vulnerability can be triggered on any page that renders a JoomSport shortcode.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity assessment. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. No versions of the vulnerability are listed in the CISA KEV catalog. Exploitation requires an authenticated attacker who has obtained the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode, making this a local, authenticated vulnerability that can be triggered on the affected WordPress site.
OpenCVE Enrichment