The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.426
EPSS Ranking 97.3%