CVE-2025-7721: JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7721?
CVE-2025-7721 is rated as a high severity vulnerability due to local file inclusion allowing unauthorized access to sensitive files.
How do I fix CVE-2025-7721?
To fix CVE-2025-7721, update the JoomSport plugin to version 5.7.4 or later.
Who is affected by CVE-2025-7721?
All users of the JoomSport plugin for WordPress versions up to and including 5.7.3 are affected by CVE-2025-7721.
What type of vulnerability is CVE-2025-7721?
CVE-2025-7721 is a Local File Inclusion (LFI) vulnerability that can be exploited to execute arbitrary PHP files.
Can CVE-2025-7721 be exploited by unauthenticated users?
Yes, CVE-2025-7721 can be exploited by unauthenticated attackers, making it a critical security risk.