Sceawere

Vulnerability Detail

CVE-2026-107507UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Squadeno Insecure Authorization Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
8h ago
Vendor
Unknown
Product
Squadeno
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings and date of a sport they are assigned to.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-11T07:17:23.087Z",
  "pubdate": "2026-10-11T07:17:23.087Z",
  "executiveSummary": "The Squadeno WordPress plugin, in versions prior to 1.12.0, contains an insecure authorization vulnerability stemming from incomplete access control enforcement.\nThis vulnerability allows authenticated users with the low-privileged 'Trainer' role to perform unauthorized modifications to sport-related data that they are assigned to manage.\nSpecifically, the plugin fails to validate authorization constraints across all available entry points for saving sport configurations.\nConsequently, a Trainer can manipulate sensitive attributes including the section, age group, author, password protection status, comment settings, and publication date of their assigned sports.\nThis impact constitutes a broken access control issue, potentially leading to unauthorized data modification, content manipulation, and a violation of the principle of least privilege.\nExploitation requires the attacker to be authenticated as a user with the 'Trainer' role. No further exploitation requirements are necessary, as the flaw exists in the application's internal authorization logic.",
  "technicalDetails": "The vulnerability resides within the authorization logic of the Squadeno plugin's data persistence layer. The core issue is an inconsistent implementation of access control checks when processing 'save' or 'update' requests for sport entities.\nWhile the plugin intends to restrict Trainers to only modify assigned sports, it fails to enforce these restrictions uniformly across all API endpoints or hooks utilized to save this data. This allows an authenticated Trainer, when interacting with the affected functionality, to bypass intended restrictions through specific, though inadequately validated, execution paths.\nThe root cause is an insecure implementation of the authorization model, where secondary validation mechanisms are absent or flawed in certain code paths responsible for handling 'save' operations. Specifically, the component responsible for processing sport metadata fails to re-verify if the authenticated user has the necessary permissions to modify fields such as the post author, password, or comment configurations for the specific object ID being submitted.\nThe attack flow proceeds as follows: 1. An attacker authenticates to the WordPress dashboard with a 'Trainer' account. 2. The attacker navigates to the sport editing interface or intercepts the request sent when saving a sport configuration. 3. The attacker modifies the request payload to include unauthorized fields such as 'post_author', 'post_password', or 'comment_status', or alters parameters such as the 'section' or 'age group' which may be restricted based on administrative assignment. 4. Due to the lack of exhaustive validation on the server side, the application processes the request, updating the database record with the attacker-supplied, unauthorized values.\nThe vulnerability affects versions of the Squadeno plugin prior to 1.12.0. Because the flaw is intrinsic to the plugin's architectural handling of user input and authorization, it remains exploitable as long as the vulnerable version is active and the Trainer role is assigned to a user account, regardless of network exposure.\nPost-exploitation impact includes the ability for lower-privileged users to modify data they are explicitly meant to be restricted from changing. This could lead to unauthorized visibility (via password change), content manipulation, or alteration of site structure (via section/date changes), undermining the integrity and availability of the sport management features within the WordPress installation."
}
CVE-2026-107507: Squadeno Insecure Authorization Vulnerability (LOW Severity, CVSS: 2.7) | Sceawere