Time-Based SQL Injection in JoomSport Plugin for WordPress
CVE-2026-11920
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-11920?
The JoomSport plugin for WordPress is affected by a time-based SQL injection vulnerability through the 'order' parameter, impacting all versions up to 5.7.9. This flaw arises from inadequate escaping of user-supplied parameters and insufficient preparation in the SQL query, enabling authenticated attackers with administrator-level access to inject additional SQL queries. The absence of nonce or CSRF protection on the GET request creates an opportunity for unauthenticated attackers, who can deceive an authenticated administrator into sending a malicious request. Notably, this vulnerability necessitates the presence of a non-empty 'orderby' parameter alongside the 'order' parameter to be triggered.
Affected Version(s)
JoomSport β for Sports: Team & League, Football, Hockey & more 0 <= 5.7.9