The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.316
EPSS Ranking 96.6%