← WordPress Vulnerabilities
WordPress security by component

Football Pool

Football Pool (football-pool) is a WordPress plugin with 9 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.5.

Plugin slug: football-pool

CVE-2026-8790: Football Pool shoutbox error reflection permits cross-site scripting

Football Pool through 2.13.4 reflects the raw shouttext POST value into the Shoutbox widget's textarea with printf('%s', ...) when a submission fails its nonce check, has empty text or cannot be saved. Because the value is not HTML-escaped, an unauthenticated attacker can prepare a cross-origin POST that breaks out of the textarea. Script executes if a logged-in victim with Subscriber access or higher is induced to submit the crafted request to a page containing the Shoutbox widget.

PublishedAug 05, 2026
Known safe version> 2.13.4
Published vulnerabilities for football-pool
Safe version
Aug 05, 2026 CVE-2026-8790
Football Pool shoutbox error reflection permits cross-site scripting
Football Pool through 2.13.4 reflects the raw shouttext POST value into the Shoutbox widget's textarea with printf('%s', ...) when a submission fails its nonce check, has empty text or cannot be saved. Because the value is not HTML-escaped, an unauthenticated attacker can prepare a cross-origin POST that breaks out of the textarea. Script executes if a logged-in victim with Subscriber access or higher is induced to submit the crafted request to a page containing the Shoutbox widget.
> 2.13.4
CVE6.1
NVDPending
Sep 09, 2025 CVE-2025-58987
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Jun 27, 2025 CVE-2025-53280
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Jun 19, 2025 CVE-2025-5490
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.5
NVD4.8
Mar 27, 2025 CVE-2025-30764
Football Pool: Cross-site request forgery
Football Pool is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Aug 12, 2024 CVE-2024-43139
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Aug 12, 2024 CVE-2024-43130
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.9
NVDPending
Mar 27, 2024 CVE-2024-29802
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Aug 20, 2019 CVE-2017-18524
Football Pool: Cross-site scripting
Football Pool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD6.1