WordPress JoomSport plugin before 5.2.8 contains a SQL injection vulnerability. The plugin does not properly sanitize and escape a parameter before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
id: CVE-2022-4050
info:
name: WordPress JoomSport <5.2.8 - SQL Injection
author: theamanrawat
...