
CVE-2025-15368 The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This… https://www.cve.org/CVERecord?id=CVE-2025-15368
Post summary
The SportsPress WordPress plugin is vulnerable to Local File Inclusion (CVE-2025-15368) affecting all versions up to 2.7.26 via the shortcode 'template_name' attribute; no PoC, exploit, patch, or active exploitation is mentioned.



