CVE-2026-12133: JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsportseasongroupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport group records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12133?
The severity of CVE-2026-12133 is medium with a score of 4.3.
What is CVE-2026-12133 about?
CVE-2026-12133 pertains to the JoomSport WordPress plugin, which has a missing authorization issue allowing arbitrary group deletion.
How do I fix CVE-2026-12133?
To fix CVE-2026-12133, update the JoomSport plugin to version 5.7.9 or later.
What versions are affected by CVE-2026-12133?
CVE-2026-12133 affects JoomSport versions up to and including 5.7.8.
Who is impacted by CVE-2026-12133?
Users of the JoomSport plugin for WordPress, specifically those with Subscriber+ roles, are impacted by CVE-2026-12133.