{
 "id": "WPSEC-2026-0758",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0758/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0758/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0758/index.md",
 "title": "BP Profile Search <= 5.9 - Unauthenticated Local File Inclusion via 'bps_directory' Cookie and 'template' Shortcode Attribute",
 "description": "The BP Profile Search plugin for WordPress is vulnerable to Local File Inclusion via the directory template names read from the 'bps_directory' cookie during AJAX requests and from the 'template' attribute of the [bps_directory] shortcode in all versions up to, and including, 5.9. This is due to insufficient sanitization of the template names before they are passed to BuddyPress template location. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded or otherwise placed on the server.",
 "plugin": {
  "slug": "bp-profile-search",
  "name": "BP Profile Search",
  "full_name": "BP Profile Search",
  "wordpress_org": "https://wordpress.org/plugins/bp-profile-search/",
  "advisories_url": "https://wpsec.com/vuln/plugin/bp-profile-search/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/bp-profile-search"
 },
 "type": "LFI",
 "cwe": [
  "CWE-98"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 9.8,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "severity": "Critical"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "6.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 6.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "6.0",
 "remediation": "Update to 6.0 or later.",
 "fix_released": "2026-10-10T06:04:27+00:00",
 "published": "2026-10-11T06:41:45+00:00",
 "updated": "2026-10-10T14:53:48.062808+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0758/",
  "https://plugins.svn.wordpress.org/bp-profile-search/tags/6.0/",
  "https://wordpress.org/plugins/bp-profile-search/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/bp-profile-search",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-11"
 }
}