Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The NewsPlus Shortcodes plugin for WordPress contains an improper control of a filename used in an include or require statement, classified as CWE‑98. This flaw allows an attacker to read arbitrary files from the server that are accessible to the web‑server process.

Affected Systems

WordPress installations that have the NewsPlus Shortcodes plugin version 4.2.0 or older installed are affected. The plugin is developed by SaurabhSharma and is distributed through the WordPress plugin repository. No other WordPress components are impacted by this vulnerability.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is reported as less than 1 %, indicating that exploitation activity is currently very low. It is not listed in CISA's KEV catalog. Based on the description, the likely attack vector involves an attacker inserting a crafted filename into a shortcode or other user‑controlled input that the plugin passes directly to an include operation. This does not require elevated server permissions and can be performed by unauthenticated users who can add or edit content, or by authenticated users with publishing rights.

Generated by OpenCVE AI on August 1, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the NewsPlus Shortcodes plugin to a version newer than 4.2.0 as soon as it becomes available.
  • If an update is not yet available, deactivate or uninstall the plugin to prevent the vulnerability from being exploitable.
  • Configure file system permissions so that the web server can access only the directories required for WordPress operation, and configure the web server to block HTTP access to confidential files such as configuration files and logs.

Generated by OpenCVE AI on August 1, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Saurabhsharma
Saurabhsharma newsplus Shortcodes
Wordpress
Wordpress wordpress
Vendors & Products Saurabhsharma
Saurabhsharma newsplus Shortcodes
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.
Title WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Saurabhsharma Newsplus Shortcodes
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:49.469Z

Reserved: 2026-06-25T08:05:08.366Z

Link: CVE-2026-57798

cve-icon Vulnrichment

Updated: 2026-07-13T16:01:54.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')