SQL Injection Vulnerability in JoomSport Plugin for WordPress
CVE-2026-6929
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 May 2026
What is CVE-2026-6929?
The JoomSport plugin for WordPress has a vulnerability that allows unauthenticated attackers to perform time-based blind SQL injection through the 'sortf' parameter. This issue arises from inadequate escaping of user-supplied input and insufficient preparation of the underlying SQL queries. As a result, attackers can introduce malicious SQL statements, potentially leading to unauthorized access to sensitive database information.
Affected Version(s)
JoomSport β for Sports: Team & League, Football, Hockey & more 0 <= 5.7.7