Review
Squadeno
CVE published 2026-10-11
CVE-2026-107507
The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings, and date of a sport they are assigned to. This vulnerability allows unauthorized changes to sports data, potentially impacting data integrity and confidentiality. WordPress adm [truncated]