BP Profile Search <= 5.9 - Unauthenticated Local File Inclusion via 'bps_directory' Cookie and 'template' Shortcode Attribute
- ID
- WPSEC-2026-0758
- Plugin
- BP Profile Search (bp-profile-search)
- Affected
- all versions before 6.0
- Remediation
- Update to 6.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-98
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-11
- Attack surface
- BP Profile Search on WPSec AttackSurface
- Fix released
- Published
Description
The BP Profile Search plugin for WordPress is vulnerable to Local File Inclusion via the directory template names read from the 'bps_directory' cookie during AJAX requests and from the 'template' attribute of the [bps_directory] shortcode in all versions up to, and including, 5.9. This is due to insufficient sanitization of the template names before they are passed to BuddyPress template location. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded or otherwise placed on the server.
References
- https://wpsec.com/vuln/WPSEC-2026-0758/
- https://plugins.svn.wordpress.org/bp-profile-search/tags/6.0/
- https://wordpress.org/plugins/bp-profile-search/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS