Impact
The JoomSport plugin for WordPress, versions up to and including 5.7.9, is vulnerable to time‑based SQL Injection via the ‘event’ shortcode attribute. Insufficient escaping of this user‑supplied parameter and the lack of proper preparation on the existing SQL query allow an authenticated user with contributor‑level access or higher to append additional SQL statements that can read sensitive data from the database. The injection is performed by embedding the shortcode in a post or page, which any user with the required role can do.
Affected Systems
WordPress sites using the JoomSport – for Sports: Team & League, Football, Hockey & more plugin, any version up to 5.7.9.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires an authenticated user with at least contributor permissions who can embed the risky shortcode in a post or page, enabling the injection of arbitrary SQL queries to exfiltrate data.
OpenCVE Enrichment