CVE-2026-107507
Received Received - Intake

Squadeno Plugin Trainer Role Sport Modification Vulnerability

Vulnerability report for CVE-2026-107507, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings and date of a sport they are assigned to.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Squadeno 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107507 is an Incorrect Authorization vulnerability in the Squadeno WordPress plugin versions before 1.12.0. It allows users with the lowest-tier Trainer role to modify attributes of a sport they are assigned to, such as section, age group, author, password, comment settings, and date. This happens because the plugin does not enforce its restrictions on all methods of saving a sport.

Detection Guidance

Check the installed version of the Squadeno WordPress plugin. If it is below 1.12.0, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details.

Impact Analysis

If you use the Squadeno plugin with a Trainer role, an attacker with this role could alter sport details they manage, potentially leading to unauthorized changes in content, access, or metadata. This could disrupt operations or misrepresent information.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves unauthorized modification of sport attributes by low-privilege users in a WordPress plugin. However, if the plugin handles personal or sensitive data related to sports or users, unauthorized changes could potentially lead to data integrity issues or breaches, indirectly impacting compliance.

Mitigation Strategies

Update the Squadeno WordPress plugin to version 1.12.0 or later to fix the vulnerability. Ensure users with the Trainer role are not granted unnecessary permissions that could allow unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107507. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart