Time-Based SQL Injection in JoomSport Plugin for WordPress
CVE-2026-11920

4.9MEDIUM

What is CVE-2026-11920?

The JoomSport plugin for WordPress is affected by a time-based SQL injection vulnerability through the 'order' parameter, impacting all versions up to 5.7.9. This flaw arises from inadequate escaping of user-supplied parameters and insufficient preparation in the SQL query, enabling authenticated attackers with administrator-level access to inject additional SQL queries. The absence of nonce or CSRF protection on the GET request creates an opportunity for unauthenticated attackers, who can deceive an authenticated administrator into sending a malicious request. Notably, this vulnerability necessitates the presence of a non-empty 'orderby' parameter alongside the 'order' parameter to be triggered.

Affected Version(s)

JoomSport – for Sports: Team & League, Football, Hockey & more 0 <= 5.7.9

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicolas Decayeux
.