Impact
The NewsPlus Shortcodes plugin for WordPress contains an improper control of a filename used in an include or require statement, classified as CWE‑98. This flaw allows an attacker to read arbitrary files from the server that are accessible to the web‑server process.
Affected Systems
WordPress installations that have the NewsPlus Shortcodes plugin version 4.2.0 or older installed are affected. The plugin is developed by SaurabhSharma and is distributed through the WordPress plugin repository. No other WordPress components are impacted by this vulnerability.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is reported as less than 1 %, indicating that exploitation activity is currently very low. It is not listed in CISA's KEV catalog. Based on the description, the likely attack vector involves an attacker inserting a crafted filename into a shortcode or other user‑controlled input that the plugin passes directly to an include operation. This does not require elevated server permissions and can be performed by unauthenticated users who can add or edit content, or by authenticated users with publishing rights.
OpenCVE Enrichment