CVE-2025-15368 | SportsPress Plugin up to 2.7.26 on WordPress Shortcode template_name file inclusion
A vulnerability was found in SportsPress Plugin up to 2.7.26 on WordPress. It has been declared as critical. Affected by this issue is the function template_name of the component Shortcode Handler. Executing a manipulation can lead to file inclusion.
The identification of this vulnerability is CVE-2025-15368. The attack may be launched remotely. There is no exploit available.