Impact
An attacker who can play the role of a Contributor on a WordPress site can use the SportsPress Pro plugin to request any file stored on the local filesystem. This vulnerability is a Local File Inclusion flaw (CWE‑98) that allows the reading of arbitrary files such as configuration files, authentication credentials, or application logs, thereby threatening the confidentiality of the system. There is no indication that the flaw permits code execution, so the risk is confined to data disclosure.
Affected Systems
WordPress installations running the ThemeBoy SportsPress Pro plugin versions 2.7.29 and earlier are impacted. All sites that have these versions deployed and that grant Contributor or higher privileges to any user may be affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high score; <1% suggests that exploitation is unlikely. The vulnerability is not acknowledged in CISA’s KEV catalog. The most probable attack vector is via the web interface, requiring an authenticated Contributor account; attackers can trigger the file inclusion without needing higher privileges or additional system access, resulting primarily in confidential data leaks.
OpenCVE Enrichment