Local File Inclusion in Breaking News WP Plugin for WordPress
CVE-2026-4280
6.5MEDIUM
What is CVE-2026-4280?
The Breaking News WP plugin for WordPress is susceptible to Local File Inclusion due to vulnerabilities in its AJAX endpoint. The lack of authorization checks and CSRF validation, along with inadequate path validation when the brnwp_theme option value is processed, enables authenticated attackers with Subscriber-level access and above to manipulate the include() function. This flaw permits attackers to override the brnwp_theme option with a directory traversal payload, resulting in potential exposure and inclusion of sensitive files from the server when the shortcode is executed.
Affected Version(s)
Breaking News WP 0 <= 1.3