Description
Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP breaking-news-wp allows Cross Site Request Forgery.This issue affects Breaking News WP: from n/a through <= 1.3.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Breaking News WP plugin contains a Cross‑Site Request Forgery flaw that lets an attacker change plugin settings without proper authorization. By directing an authenticated user to a specially crafted URL, the attacker activates the plugin’s settings update endpoint which lacks CSRF protection. The vulnerability is classified as CWE‑352 and carries a CVSS score of 6.5, indicating moderate severity. Attacker gains the same rights as the victim, enabling stealthy configuration changes such as disabling notifications or altering the plugin’s behavior.

Affected Systems

WordPress sites running Breaking News WP from doit with any version up to and including 1.3 are vulnerable. All installations of the plugin in that version range are affected.

Risk and Exploitability

With a CVSS of 6.5, the flaw is considered moderate, while the EPSS score of less than 1% and absence from CISA’s KEV catalog suggest low current exploitation likelihood. However, the exploit requires an authenticated user with write access, which is common for editors and administrators. A social‑engineering attack or a malicious link can trigger the vulnerability, leading to unauthorized configuration changes that may disrupt site operation or redirect traffic.

Generated by OpenCVE AI on May 2, 2026 at 08:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Breaking News WP plugin to a version that includes a CSRF fix, such as 1.4 or later.
  • If upgrading is not immediately possible, remove or restrict the plugin’s settings interface to administrators only by modifying role capabilities or using a plugin that limits access to high‑privilege users.
  • Implement an additional CSRF token or nonce on all state‑changing requests through a security plugin or custom code to block unauthorized requests.

Generated by OpenCVE AI on May 2, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9265 Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3. Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP breaking-news-wp allows Cross Site Request Forgery.This issue affects Breaking News WP: from n/a through <= 1.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3.
Title WordPress Breaking News WP Plugin <= 1.3 - CSRF to Settings Change vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.238Z

Reserved: 2025-04-01T13:19:14.438Z

Link: CVE-2025-31751

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:55.311Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:11.533

Modified: 2026-04-23T15:28:12.917

Link: CVE-2025-31751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T08:45:38Z

Weaknesses