Junglewise Threat Intelligence

CVE-2026-57798: SaurabhSharma NewsPlus Shortcodes Local File Inclusion

CVE-2026-57798 · Severity: high · CVSS 7.5 · Published 2026-07-13

Executive brief

The NewsPlus Shortcodes plugin for WordPress, which provides custom layout elements for websites, contains a security flaw that could allow an attacker to access sensitive server files. By exploiting this vulnerability, an authorized user with low-level permissions (such as a contributor) could potentially view configuration files containing database credentials or other private information. This could lead to a full compromise of the website's data and operations.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the SaurabhSharma NewsPlus Shortcodes plugin (newsplus-shortcodes) through version 4.2.0. The flaw stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An authenticated attacker with 'Contributor' level privileges can exploit this to include arbitrary local files from the server. Successful exploitation could allow the attacker to read sensitive files, such as wp-config.php, potentially leading to full database takeover or remote code execution if combined with other techniques. As of the advisory date, no official patch is available.

Affected products

  • SaurabhSharma NewsPlus Shortcodes (newsplus-shortcodes) <= 4.2.0

Timeline

  • 2026-01-03: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-07-02: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE-2026-57798

References