CVE-2026-4280Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option value is passed directly to an include() statement in the brnwp_show_breaking_news_wp() shortcode handler. While sanitize_text_field() is applied to user input, it does not strip directory traversal sequences (../). This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the brnwp_theme option with a directory traversal payload (e.g., ../../../../etc/passwd) and subsequently trigger file inclusion of arbitrary files on the server when the shortcode is rendered.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-25: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-2304-25
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-231
Disclosure1
2026-04-251
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4280-breaking-news-wp-version-1-3-medium-vulnerability-proof-of-concept CVE-2026-4280 #WordPress plugin #vulnerability breaking-news-wp #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The content announces CVE-2026-4280—a medium‑severity WordPress plugin vulnerability—and highlights a proof‑of‑concept, without detailing patches, exploitation status, or technical specifics.

    0000047
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4280 The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpo… https://www.cve.org/CVERecord?id=CVE-2026-4280

    Post summary

    The Breaking News WP plugin for WordPress has a local file inclusion vulnerability (CVE-2026-4280) affecting all versions up to 1.3, caused by the brnwp_ajax_form AJAX endpoint. No PoC, exploit, patch, or evidence of active exploitation is provided.

    00000149
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4280 Local File Inclusion in Breaking News WP Plugin Through Directory Traversal https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4280

    Post summary

    The text announces a local file inclusion vulnerability (CVE‑2026‑4280) in the Breaking News WP plugin that exploits directory traversal, but it does not provide a PoC, exploit code, usage evidence, or patch information.

    0000068
    4.0K followersView on X

Explore more