CVE-2026-12134: JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12134?
CVE-2026-12134 has a medium severity rating of 4.3.
How do I fix CVE-2026-12134?
To fix CVE-2026-12134, update the JoomSport plugin to a version higher than 5.7.8.
What is the impact of CVE-2026-12134?
CVE-2026-12134 allows authenticated users to create or modify arbitrary groups without proper authorization.
Is CVE-2026-12134 present in all versions of JoomSport?
Yes, CVE-2026-12134 is present in all versions of JoomSport up to and including 5.7.8.
What type of vulnerability is CVE-2026-12134?
CVE-2026-12134 is an authorization bypass vulnerability affecting the JoomSport plugin.