# BP Profile Search <= 5.9 - Unauthenticated Local File Inclusion via 'bps_directory' Cookie and 'template' Shortcode Attribute

- **ID:** WPSEC-2026-0758
- **Plugin:** BP Profile Search (`bp-profile-search`), https://wordpress.org/plugins/bp-profile-search/
- **Affected versions:** all versions before 6.0
- **Fixed in:** 6.0 (Update to 6.0 or later.)
- **Severity:** Critical 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-98
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bp-profile-search
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0758/

## Description

The BP Profile Search plugin for WordPress is vulnerable to Local File Inclusion via the directory template names read from the 'bps_directory' cookie during AJAX requests and from the 'template' attribute of the [bps_directory] shortcode in all versions up to, and including, 5.9. This is due to insufficient sanitization of the template names before they are passed to BuddyPress template location. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded or otherwise placed on the server.

## References

- https://wpsec.com/vuln/WPSEC-2026-0758/
- https://plugins.svn.wordpress.org/bp-profile-search/tags/6.0/
- https://wordpress.org/plugins/bp-profile-search/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0758/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
