SportsPress WordPress Plugin Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in the SportsPress plugin for WordPress, affecting all versions through 2.7.26. The vulnerability arises from the 'template_name' attribute in shortcodes, allowing authenticated attackers with contributor-level permissions or higher to include and execute arbitrary files on the server. This exploitation could bypass access controls, access sensitive data, or execute PHP code from uploaded files.

Impact

Exploitation of this vulnerability could lead to unauthorized file inclusion, allowing execution of arbitrary PHP code on the server. This could be used to bypass access controls, access sensitive information, or execute malicious code, especially in cases where uploaded files can be included as PHP scripts.

Reproduction

To reproduce this vulnerability, an authenticated user with contributor-level or higher permissions can use a shortcode that includes the 'template_name' attribute. The attribute can be crafted to include a file from the server, exploiting the local file inclusion vulnerability.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Feb 4, 2026, 2:21 PM
Updated: Feb 4, 2026, 5:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.3
remediation
0.0
relevance
2.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.