Impact
The JoomSport plugin for WordPress is vulnerable to time-based SQL Injection through the ’event’ shortcode attribute. Insufficient escaping of this user‑supplied parameter and the lack of preparation on the existing SQL query allow an authenticated user with contributor‑level access or higher to insert additional SQL statements. By doing so, attackers can extract sensitive information from the database, affecting confidentiality and potentially the integrity of stored data.
Affected Systems
JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress, versions up to and including 5.7.9.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires an authenticated user with at least contributor permissions who can embed the risky shortcode in a post or page, enabling the injection of arbitrary SQL queries to exfiltrate data.
OpenCVE Enrichment