PatchSiren cyber security CVE debrief
CVE-2026-107507 Squadeno CVE debrief
The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings, and date of a sport they are assigned to. This vulnerability allows unauthorized changes to sports data, potentially impacting data integrity and confidentiality. WordPress administrators and users with the Trainer role should assess exposure and verify the version of the Squadeno plugin.
- Vendor
- Squadeno
- Product
- Squadeno WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
WordPress administrators and users with the Trainer role should assess exposure and verify the version of the Squadeno plugin. They should also restrict Trainer role permissions to prevent unauthorized changes to sports data. Additionally, security teams and vulnerability management teams should review the vulnerability and its potential impact on their environments.
Why it matters
The Squadeno WordPress plugin vulnerability allows users with the lowest-tier Trainer role to make unauthorized changes to sports data. WordPress administrators and users with the Trainer role should assess exposure and verify the version of the plugin. The vulnerability requires verification of affected versions and potential impact.
- Verify version and update to 1.12.0 or later
- Restrict Trainer role permissions to prevent unauthorized changes
Technical summary
The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings, and date of a sport they are assigned to. This vulnerability requires verification of affected versions and potential impact. The plugin's flawed restriction enforcement could lead to unauthorized data modifications, emphasizing the need for version verification and access control adjustments.
Defensive priority
Assess exposure and verify version; restrict Trainer role permissions
Recommended defensive actions
- Verify the version of the Squadeno WordPress plugin and update to 1.12.0 or later if necessary
- Restrict permissions for users with the Trainer role to prevent unauthorized changes to sports data
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions and potential impact. The Squadeno plugin's restrictions on saving sports data are not enforced uniformly, allowing users with the Trainer role to make unauthorized changes. This requires verification of affected versions and potential impact. Defenders should verify the plugin version and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107507 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107507
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107507 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107507
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/f02f3608-0809-4a4e-ae5f-5e89d42c4026/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.