Coaching Staffs

Coaching Staffs has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Coaching Staffs has a vendor fix available, so running the current release closes it.

All of these findings were reported by Peter Thaleikis. Coaching Staffs is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Coaching Staffs vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-13663

Coaching Staffs <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Coaching Staffs banner
Latestv1.5.3

Coaching Staffs

Mark O'Donnell

Author

Mark O'Donnell

5.0(1)
100/100
Last Updated
2025-06-13 (1y ago)
Active Installs
10+
Downloads
7,212
Requires WP
5.2+
Requires PHP
7.2+
Tested up to
WP 6.8.8
Created
2013-08-19 (13y ago)

The MSTW Coaching Staffs plugin manages coaching staff rosters for sports teams. The plugin supports multiple coaches, staffs, and teams. It provides several views of staffs including coaches table (screenshot-1), a coaches gallery (screenshot-2), and single coach profiles (screenshot-3). Samples of all of the above displays are available on the Shoal Summit Solutions Plugin Development Site. This plugin is designed to handle some challenges unique to high school coaching staffs, where coaches often coach two (or more) teams in different roles. For example, one coach can be the Head Coach of the Junior Varsity team and the Offensive Line coach for the Varsity team. That coach can be shown as the first coach on the JV staff and somewhere lower on the Varsity staff listings. Here’s how to do it: Begin by adding the Coaches using the Coaching Staffs -> All Coaches -> Add New Coach admin page. (screenshot-4 and screenshot-5) Next add the Coaching Staffs, using the Coaching Staffs -> Staffs admin page. (screenshot-6) Finally add the Staff Positions, using the Coach Staffs -> All Staff Positions -> Add New Staff Position admin page. (screenshot-7 and screenshot-8) It is important that you enter/add data in this order because the coach and staff must be entered before they can be associated with a staff position. To display a staff table via the short code enter [mstw-cs-table staff=staff-slug] on the TEXT or HTML tab, NOT the VISUAL tab, of a page, post, or text widget. You MUST provide a staff parameter or nothing will be displayed. Many other parameters are available, which you can read about on the Shoal Summit Solutions site. Looking the samples on my plugin development site is highly recommended. To learn how to install and use the single coach profile page and the coaching staff gallery page, please read the instructions on the Installation tab and on the Shoal Summit Solutions site. The plugin is internationalized and ready for translation. I am happy to help translators. A default .pot file is in the /lang directory. NOTES The Coaching Staffs plugin is part of the My Sports Team Website (MSTW) framework. Others include Schedules & Scoreboards, Team Rosters, League Standings, MSTW CSV Exporter, and Game Locations and Game Schedules (both now deprecated). All are available on WordPress.org. Helpful Links See what the plugin in action on the MSTW Dev Site -» Read the (site admin) user’s manual at shoalsummitsolutions.com -»

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C