Local File Inclusion in Breaking News WP Plugin for WordPress
CVE-2026-4280

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2026

What is CVE-2026-4280?

The Breaking News WP plugin for WordPress is susceptible to Local File Inclusion due to vulnerabilities in its AJAX endpoint. The lack of authorization checks and CSRF validation, along with inadequate path validation when the brnwp_theme option value is processed, enables authenticated attackers with Subscriber-level access and above to manipulate the include() function. This flaw permits attackers to override the brnwp_theme option with a directory traversal payload, resulting in potential exposure and inclusion of sensitive files from the server when the shortcode is executed.

Affected Version(s)

Breaking News WP 0 <= 1.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Minh Toan
.