Local File Inclusion Vulnerability in Player Leaderboard Plugin for WordPress
CVE-2025-12824
What is CVE-2025-12824?
The Player Leaderboard plugin for WordPress contains a Local File Inclusion (LFI) vulnerability that affects versions up to and including 1.0.2. This vulnerability arises from an insecure implementation of the 'player_leaderboard' shortcode, which allows authenticated users with Contributor-level access and higher to pass unsanitized values to an include() function, failing to properly validate paths. As a result, attackers can potentially include and execute arbitrary PHP files from the server, resulting in unauthorized access to sensitive data and possibly leading to full remote code execution if exploited in conjunction with file upload features.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Player Leaderboard 1.0.0 <= 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved