Authorization Bypass Vulnerability in JoomSport Plugin for WordPress
CVE-2026-12134
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 July 2026
What is CVE-2026-12134?
The JoomSport plugin for WordPress is susceptible to an authorization bypass flaw, which allows authenticated users with subscriber-level access and above to manipulate season groups. This vulnerability arises from the plugin's failure to adequately verify user permissions when executing actions. Specifically, an attacker can create new season groups or alter existing group names, participants, and round-type settings. The attack requires the acquisition of a nonce value, which is exposed on certain frontend pages displaying JoomSport shortcodes, further complicating user management and security.
Affected Version(s)
JoomSport β for Sports: Team & League, Football, Hockey & more 0 <= 5.7.8