Access violation vulnerability in SportsPress – Sports Club & League Manager 2.7.20

The SportsPress plugin for WordPress, which manages sports clubs and leagues, has a security vulnerability that allows unauthorized changes to be made to the data. This is because the add_notices() function does not have a capability check in versions 2.7.20 and below. As a result, attackers who have subscriber-level access or higher can dismiss important notices.

Detected in:

SportsPress – Sports Club & League Manager open vulnerable versions: >= * <= 2.7.20

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.