Medium 6.5
2025-09-09< 2.13.0
CVE-2025-58987
Minimum safe version
2.13.0
Update to 2.13.0 or later to address 11 fixable vulnerabilities
CVE-2025-58987
CVE-2025-53280
Football Pool <= 2.12.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2025-30764
CVE-2024-43139
CVE-2024-43130
CVE-2024-29802
WordPress Football Pool Plugin <= 2.11.3 is vulnerable to Cross Site Scripting (XSS)
Football pool <= 2.11.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Football Pool Plugin <= 2.6.3 - Authenticated Arbitrary File Upload Vulnerability
CVE-2017-18524