What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.
Explanation of Vulnerability in Simple Terms
SportsPress versions up to 2.7.20 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can change information without the plugin verifying their permissions. The vulnerability affects data integrity but does not expose sensitive information or disrupt site availability.
What an attacker can do
Modify data in SportsPress without proper permission checks.
Potential impact on your site
Unauthorized users can alter sports league, club, or event data depending on plugin configuration.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities