Junglewise Threat Intelligence

CVE-2026-13010: Beardev JoomSport SQL injection in event shortcode attribute

CVE-2026-13010 · Severity: medium · CVSS 6.5 · Published 2026-07-10

Technologies: BearDev JoomSport. Vendors: BearDev.

Executive brief

JoomSport is a WordPress plugin used to manage sports leagues, teams, and player statistics. A security flaw in the plugin allows users with contributor-level access or higher to perform unauthorized database queries. This could lead to the exposure of sensitive information stored in the website's database, potentially compromising user data or site configuration.

Technical details

A time-based SQL injection vulnerability exists in the JoomSport WordPress plugin due to insufficient escaping of the 'event' attribute within shortcode processing and a lack of SQL query preparation. The flaw is located in the shortcode handling logic and the player retrieval classes. Authenticated attackers with at least 'contributor' privileges can exploit this by embedding a malicious shortcode into a post or page. By injecting SQL commands, an attacker can perform blind inference to extract sensitive information from the WordPress database. The issue affects all versions up to and including 5.7.9.

Affected products

  • beardev JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.9

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats