CVE-2025-15368Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-04: 3Mentions · 2026-02-09: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-09: 102-0402-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-043
Disclosure3
2026-02-091
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-15368 The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This… https://www.cve.org/CVERecord?id=CVE-2025-15368

    Post summary

    The SportsPress WordPress plugin is vulnerable to Local File Inclusion (CVE-2025-15368) affecting all versions up to 2.7.26 via the shortcode 'template_name' attribute; no PoC, exploit, patch, or active exploitation is mentioned.

    00020275
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-15368 (CVSS:8.8, HIGH) is Awaiting Analysis. The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 ..https://nvd.nist.gov/vuln/detail/CVE-2025-15368 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-15368 is a Local File Inclusion vulnerability affecting SportsPress WordPress plugin versions up to 2.7.26, currently awaiting analysis with no exploit, patch, or PoC details provided.

    0000028
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15368 Local File Inclusion in WordPress SportsPress Plugin via Shortcode Template Attribute https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15368

    Post summary

    The post announces CVE‑2025‑15368, a local file inclusion vulnerability in the WordPress SportsPress plugin, providing basic details but no PoC, exploit, or mitigation information.

    0000053
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-15368 - High The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for au... https://www.thehackerwire.com/vulnerability/CVE-2025-15368/ https://t.co/R4GRwAcdK3

    Post summary

    SportsPress plugin for WordPress contains a high‑severity local file inclusion flaw in versions up to 2.7.26 via the 'template_name' shortcode, enabling attackers to read arbitrary files.

    00000104
    113 followersView on X

Explore more