The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9. This vulnerability allows authenticated attackers, with contributor-level access and above, to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure.
A critical vulnerability was discovered in JoomSport, a WordPress plugin used for sports league results management. The issue, tracked as CVE-2026-42647, is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. This vulnerability allows for Blind SQL Injection and has been rated with a CVSS score of 9.3, indicating a critical severity level.