Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext`...
- CVSS:
- 6.1
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.5
- Disclosed:
- Aug 4, 2026
CVE-2026-8790 on NVD →
Football Pool <= 2.12.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.12.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.12.6
- Fixed in:
- 2.13.0
- Disclosed:
- Sep 9, 2025
CVE-2025-58987 on NVD →
Football Pool [football-pool] < 2.13.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool allows Stored XSS. This issue affects Football Pool: from n/a through 2.12.6.
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.0
- Disclosed:
- Sep 9, 2025
CVE-2025-58987 on NVD →
Football Pool <= 2.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.12.5
- Fixed in:
- 2.12.6
- Disclosed:
- Jun 27, 2025
CVE-2025-53280 on NVD →
Football Pool [football-pool] <= 2.12.5 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool allows Stored XSS. This issue affects Football Pool: from n/a through 2.12.5.
- Affected:
- up to 2.12.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53280 on NVD →
Football Pool <= 2.12.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...
- CVSS:
- 5.5
- Affected:
- up to 2.12.4
- Fixed in:
- 2.12.5
- Disclosed:
- Jun 18, 2025
CVE-2025-5490 on NVD →
Football Pool [football-pool] < 2.12.3 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.
- Affected:
- up to 2.12.3
- Fixed in:
- 2.12.3
- Disclosed:
- Mar 27, 2025
CVE-2025-30764 on NVD →
Football Pool <= 2.12.2 - Cross-Site Request Forgery to Settings Update
medium
The Football Pool plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings granted they can trick a site administ...
- CVSS:
- 4.3
- Affected:
- up to 2.12.2
- Fixed in:
- 2.12.3
- Disclosed:
- Mar 26, 2025
CVE-2025-30764 on NVD →
Football Pool [football-pool] < 2.12.1 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.10.
- Affected:
- up to 2.12.1
- Fixed in:
- 2.12.1
- Disclosed:
- Aug 12, 2024
CVE-2024-43130 on NVD →
Football Pool [football-pool] < 2.11.10 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.9.
- Affected:
- up to 2.11.10
- Fixed in:
- 2.11.10
- Disclosed:
- Aug 12, 2024
CVE-2024-43139 on NVD →
Football Pool <= 2.11.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'answer' parameter in versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 2.11.9
- Fixed in:
- 2.11.10
- Disclosed:
- Aug 7, 2024
CVE-2024-43139 on NVD →
Football Pool <= 2.11.10 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web...
- CVSS:
- 4.4
- Affected:
- up to 2.11.10
- Fixed in:
- 2.12.1
- Disclosed:
- Aug 7, 2024
CVE-2024-43130 on NVD →
Football Pool [football-pool] < 2.11.4 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.3.
- Affected:
- up to 2.11.4
- Fixed in:
- 2.11.4
- Disclosed:
- Mar 27, 2024
CVE-2024-29802 on NVD →
Football pool <= 2.11.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.11.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 2.11.3
- Fixed in:
- 2.11.4
- Disclosed:
- Jan 8, 2024
CVE-2024-29802 on NVD →
Football Pool [football-pool] < 2.11.4 (closed)
unknown
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.11.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...
- Affected:
- up to 2.11.4
- Fixed in:
- 2.11.4
- Disclosed:
- Jan 8, 2024
Football Pool [football-pool] < 2.11.4 (closed)
unknown
Update the WordPress Football Pool plugin to the latest available version (at least 2.11.4).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Football Pool Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTM...
- Affected:
- up to 2.11.4
- Fixed in:
- 2.11.4
- Disclosed:
- Jan 8, 2024
Football Pool [football-pool] < 2.6.5 (closed)
unknown
[en] The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Aug 20, 2019
CVE-2017-18524 on NVD →
Football Pool < 2.6.5 - Cross-Site Scripting
medium
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
- CVSS:
- 6.1
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Nov 3, 2017
CVE-2017-18524 on NVD →
Football Pool [football-pool] < 2.6.4 (closed)
unknown
WordPress Football Pool Plugin Authenticated Arbitrary File Upload Vulnerability was found in 2.6.3 version. The function didn’t include any restriction on what type of files can be uploaded
Update the plugin.
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4
- Disclosed:
- Sep 13, 2017
Football Pool [football-pool] <= 2.12.4 (unfixed + closed)
unknown
- Affected:
- up to 2.12.4
- Fix:
- No patched version reported
CVE-2025-5490 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database