wp-championship
wp-championship has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2022; all 2 are fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for wp-championship has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. wp-championship is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-1967wp-championship <= 9.2 - Multiple Cross-Site Request Forgery Vulnerabilities
Read the full analysisVulnerability Records

wp-championship
Author
tuxlog
wp-championship is a plugin for wordpress letting you play a guessing game of a tournament e.g. soccer Features: define number of groups, and points given to the winner, looser of each match define teams and a team specific icons define matches finalround and pre-final round for each user you can set a substitute sends mails about current game status (optional) define game admins to edit match results shows various stats for admin and users allows to arrange tippgroups as a kind of team guessing access via XMLRPC is possible various joker features (e.g. each player may select some matches and gets double points on it) BETA a lot of data for various tournaments and leagues (German Bundesliga, WM 2018, EM 2021) interface ti OpenLeagueDB to fetch team and match data automatically Credits: Thanks go to all who support this plugin, with hints and suggestions for improvment and especially to Andy Chapman for doing a lot of tests
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C