The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport group records.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 01 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Beardev
Beardev joomsport – For Sports: Team & League, Football, Hockey & More Wordpress Wordpress wordpress |
|
| Vendors & Products |
Beardev
Beardev joomsport – For Sports: Team & League, Football, Hockey & More Wordpress Wordpress wordpress |
Wed, 01 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Jul 2026 05:00:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-01T10:42:12.169Z
Reserved: 2026-06-12T15:32:16.073Z
Link: CVE-2026-12133
Updated: 2026-07-01T10:33:59.521Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-01T15:15:03Z
Weaknesses