plugin

Sportspress Vulnerabilities

12 known security issues reported for the Sportspress WordPress plugin. Most recent disclosed Feb 4, 2026.

1 high 4 medium 1 low

Running Sportspress on your site? Check whether your installed version is affected.

Scan your site free

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] <= 2.7.26 (unfixed)

unknown

[en] The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, a...

Affected:
up to 2.7.26
Fix:
No patched version reported
Disclosed:
Feb 4, 2026

CVE-2025-15368 on NVD →

SportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowi...

CVSS:
8.8
Affected:
up to 2.7.26
Fixed in:
2.7.27
Disclosed:
Feb 3, 2026

CVE-2025-15368 on NVD →

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] < 2.7.22

unknown

[en] The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.7.22
Fixed in:
2.7.22
Disclosed:
Jul 30, 2024

CVE-2024-3986 on NVD →

SportsPress – Sports Club & League Manager <= 2.7.21 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis...

CVSS:
4.4
Affected:
up to 2.7.21
Fixed in:
2.7.22
Disclosed:
Jul 9, 2024

CVE-2024-3986 on NVD →

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] < 2.7.21

unknown

[en] Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

Affected:
up to 2.7.21
Fixed in:
2.7.21
Disclosed:
Jun 11, 2024

CVE-2024-34824 on NVD →

SportsPress – Sports Club & League Manager <= 2.7.20 - Missing Authorization to Notice Dismissal

low

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_notices() function in versions up to, and including, 2.7.20. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
3.5
Affected:
up to 2.7.20
Fixed in:
2.7.21
Disclosed:
May 9, 2024

CVE-2024-34824 on NVD →

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] < 2.7.18

unknown

[en] The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structu...

Affected:
up to 2.7.18
Fixed in:
2.7.18
Disclosed:
Mar 5, 2024

CVE-2024-1178 on NVD →

SportsPress – Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update

medium

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structure fo...

CVSS:
5.3
Affected:
up to 2.7.17
Fixed in:
2.7.18
Disclosed:
Mar 4, 2024

CVE-2024-1178 on NVD →

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] < 2.7.9

unknown

[en] The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.7.9
Fixed in:
2.7.9
Disclosed:
Dec 21, 2021

CVE-2021-24578 on NVD →

SportsPress <= 2.7.8 - Reflected Cross-Site Scripting

medium

The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.7.8
Fixed in:
2.7.9
Disclosed:
Nov 16, 2021

CVE-2021-24578 on NVD →

SportsPress &#8211; Sports Club &amp; League Manager [sportspress] < 2.7.2

unknown

[en] The SportsPress plugin before 2.7.2 for WordPress allows XSS.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Jun 9, 2020

CVE-2020-13892 on NVD →

SportsPress <= 2.7.1 - Cross-Site Scripting

medium

The SportsPress plugin before 2.7.2 for WordPress allows XSS.

CVSS:
5.4
Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Jun 7, 2020

CVE-2020-13892 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database