CVE-2025-15368
Last modified
CVE-2025-15368 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-15368?
How severe is CVE-2025-15368?
How do I fix CVE-2025-15368?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1536A vulnerability was found in Raisecom Multi-Service Intellig…7.3
- CVE-2025-15360A vulnerability was determined in newbee-mall-plus 2.0.0. Th…7.2
- CVE-2025-15363The Get Use APIs WordPress plugin before 2.0.10 executes im…5.9
- CVE-2025-15364The Download Manager plugin for WordPress is vulnerable to p…7.3
- CVE-2025-15366The imaplib module, when passed a user-controlled command, c…5.9
- CVE-2025-15367The poplib module, when passed a user-controlled command, ca…5.9
- CVE-2025-15369The Xpro Addons — 140+ Widgets for Elementor plugin for Word…5.3
- CVE-2025-1537A vulnerability was found in Harpia DiagSystem 12. It has be…6.3
- CVE-2025-15370The Shield: Blocks Bots, Protects Users, and Prevents Securi…4.3
- CVE-2025-15371A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05,…7.8
- CVE-2025-15372A weakness has been identified in youlaitech vue3-element-ad…4.8
- CVE-2025-15373A security vulnerability has been detected in EyouCMS up to …4.3
Are you affected by CVE-2025-15368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
