CVE-2013-1852: Kolja Schleich Leaguemanager
High severity, CVSS 7.5. EPSS: 5.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.
Affected products
- Kolja Schleich Leaguemanager: up to and including 3.8; version 1.0 only; version 1.1 only; version 1.2 only; version 1.2.1 only; version 1.2.2 only; …
Published 2014-02-05. Last modified 2026-06-16.