SportsPress – Sports Club & League Manager [sportspress] <= 2.7.26 (unfixed)
unknown
[en] The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, a...
- Affected:
- up to 2.7.26
- Fix:
- No patched version reported
- Disclosed:
- Feb 4, 2026
CVE-2025-15368 on NVD →
SportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode
high
The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowi...
- CVSS:
- 8.8
- Affected:
- up to 2.7.26
- Fixed in:
- 2.7.27
- Disclosed:
- Feb 3, 2026
CVE-2025-15368 on NVD →
SportsPress – Sports Club & League Manager [sportspress] < 2.7.22
unknown
[en] The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.7.22
- Fixed in:
- 2.7.22
- Disclosed:
- Jul 30, 2024
CVE-2024-3986 on NVD →
SportsPress – Sports Club & League Manager <= 2.7.21 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis...
- CVSS:
- 4.4
- Affected:
- up to 2.7.21
- Fixed in:
- 2.7.22
- Disclosed:
- Jul 9, 2024
CVE-2024-3986 on NVD →
SportsPress – Sports Club & League Manager [sportspress] < 2.7.21
unknown
[en] Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.
- Affected:
- up to 2.7.21
- Fixed in:
- 2.7.21
- Disclosed:
- Jun 11, 2024
CVE-2024-34824 on NVD →
SportsPress – Sports Club & League Manager <= 2.7.20 - Missing Authorization to Notice Dismissal
low
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_notices() function in versions up to, and including, 2.7.20. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- CVSS:
- 3.5
- Affected:
- up to 2.7.20
- Fixed in:
- 2.7.21
- Disclosed:
- May 9, 2024
CVE-2024-34824 on NVD →
SportsPress – Sports Club & League Manager [sportspress] < 2.7.18
unknown
[en] The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structu...
- Affected:
- up to 2.7.18
- Fixed in:
- 2.7.18
- Disclosed:
- Mar 5, 2024
CVE-2024-1178 on NVD →
SportsPress – Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update
medium
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structure fo...
- CVSS:
- 5.3
- Affected:
- up to 2.7.17
- Fixed in:
- 2.7.18
- Disclosed:
- Mar 4, 2024
CVE-2024-1178 on NVD →
SportsPress – Sports Club & League Manager [sportspress] < 2.7.9
unknown
[en] The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 2.7.9
- Fixed in:
- 2.7.9
- Disclosed:
- Dec 21, 2021
CVE-2021-24578 on NVD →
SportsPress <= 2.7.8 - Reflected Cross-Site Scripting
medium
The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.9
- Disclosed:
- Nov 16, 2021
CVE-2021-24578 on NVD →
SportsPress – Sports Club & League Manager [sportspress] < 2.7.2
unknown
[en] The SportsPress plugin before 2.7.2 for WordPress allows XSS.
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 9, 2020
CVE-2020-13892 on NVD →
SportsPress <= 2.7.1 - Cross-Site Scripting
medium
The SportsPress plugin before 2.7.2 for WordPress allows XSS.
- CVSS:
- 5.4
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Jun 7, 2020
CVE-2020-13892 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database