Executive brief
Beardev JoomSport, a WordPress plugin used for managing sports leagues and results, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database. Successful exploitation could lead to the theft of sensitive information, such as user data or site configuration details, and potentially disrupt site operations.
Technical details
A blind SQL injection vulnerability exists in the Beardev JoomSport plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is present in versions up to and including 5.7.7. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected component, allowing them to execute arbitrary SQL queries against the backend database. This can be used to extract sensitive information or cause minor availability issues. The vulnerability has been addressed in version 5.7.8.
Affected products
- Beardev JoomSport <= 5.7.7
Timeline
- 2026-02-23: other: Reported by researcher daroo
- 2026-04-29: advisory: Patchstack advisory published
- 2026-06-11: disclosed: CVE published to NVD