SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57798

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in NewsPlus Shortcodes allows for improper control of filenames in PHP, enabling local file inclusion attacks. This could lead to unauthorized access to sensitive files on the server, potentially compromising the integrity and confidentiality of the system. Developers and administrators using versions up to 4.2.0 should prioritize patching this issue to mitigate the risk of exploitation.

CVE
CVE-2026-57798
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.