BP Profile Search <= 5.9 - Unauthenticated Local File Inclusion via 'bps_directory' Cookie and 'template' Shortcode Attribute

Critical 9.8 CWE-98Fixed in 6.0
ID
WPSEC-2026-0758
Plugin
BP Profile Search (bp-profile-search)
Affected
all versions before 6.0
Remediation
Update to 6.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-98
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-11
Attack surface
BP Profile Search on WPSec AttackSurface
Fix released
Published

Description

The BP Profile Search plugin for WordPress is vulnerable to Local File Inclusion via the directory template names read from the 'bps_directory' cookie during AJAX requests and from the 'template' attribute of the [bps_directory] shortcode in all versions up to, and including, 5.9. This is due to insufficient sanitization of the template names before they are passed to BuddyPress template location. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded or otherwise placed on the server.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0