Executive brief
The JoomSport plugin for WordPress, which is used to manage sports leagues and team statistics, contains a security flaw that allows unauthorized individuals to access the website's database. By sending a specially crafted web request, an attacker can bypass security measures to extract sensitive information, such as user details or site configuration data. This could lead to a significant data breach or provide a foothold for further attacks on the website.
Technical details
The JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection due to insufficient escaping on the 'sortf' parameter and a lack of sufficient preparation on existing SQL queries within the class-jsport-getplayers.php and class-jsport-playerlist.php files. An unauthenticated attacker can exploit this by appending malicious SQL commands to legitimate queries via a network request. Because the vulnerability is time-based blind, the attacker can infer data from the database based on the time the server takes to respond to specific queries. This can be used to extract sensitive information, including user credentials and site metadata. The issue affects all versions up to and including 5.7.7.
Affected products
- BearDev JoomSport – for Sports: Team & League, Football, Hockey & more Up to and including 5.7.7
Timeline
- 2026-05-13: disclosed: Initial publication of the vulnerability advisory.
References
- https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.5/sportleague/base/wordpress/classes/class-jsport-getplayers.php
- https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.5/sportleague/classes/objects/class-jsport-playerlist.php
- https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/sportleague/base/wordpress/classes/class-jsport-getplayers.php
- https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/sportleague/classes/objects/class-jsport-playerlist.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3516487%40joomsport-sports-league-results-management&new=3516487%40joomsport-sports-league-results-management&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/28b730b3-4260-414f-8a4a-65ba5509449b?source=cve