Breaking News WP Security & Risk Analysis

wordpress.org/plugins/breaking-news-wp

Show in every place your Free and Custom Breaking News Bar

400 active installs v1.3 PHP 7.1.16+ WP 4.8+ Updated Jul 29, 2019
breaking-newsbreaking-news-tickerbreaking-news-wp-pluginnews-tickernews-ticker-plugin
43
D · High Risk
CVEs total2
Unpatched2
Last CVEApr 1, 2025
Safety Verdict

Is Breaking News WP Safe to Use in 2026?

High Risk

Score 43/100

Breaking News WP carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Apr 1, 2025Updated 6yr ago
Risk Assessment

The "breaking-news-wp" v1.3 plugin exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and has no file operations or external HTTP requests, significant concerns arise from its entry points and historical vulnerability patterns. The presence of one unprotected AJAX handler presents a direct attack vector. The plugin's vulnerability history, with two currently unpatched medium severity CVEs, both related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), is a major red flag. This pattern indicates a recurring weakness in how user input is handled or how actions are protected. The lack of nonce checks on the unprotected AJAX handler, coupled with the historical XSS vulnerabilities, suggests that malicious actors could potentially inject scripts or perform unauthorized actions. The limited output escaping (28% properly escaped) further exacerbates the XSS risk, as data displayed to users may not be properly sanitized. Overall, the plugin has some strengths in its secure handling of database queries, but the unprotected entry points and persistent historical vulnerabilities create a notable risk profile.

Key Concerns

  • Unprotected AJAX handler
  • 2 unpatched medium severity CVEs
  • Limited output escaping (28% proper)
  • No nonce checks on AJAX handler
  • Historical XSS and CSRF vulnerabilities
Vulnerabilities
2

Breaking News WP Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-31750medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Breaking News WP <= 1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
CVE-2025-31751medium · 4.3Cross-Site Request Forgery (CSRF)

Breaking News WP <= 1.3 - Cross-Site Request Forgery to Settings Update

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Breaking News WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
15 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

28% escaped54 total outputs
Attack Surface
1 unprotected

Breaking News WP Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_brnwp_ajax_formbreaking-news.php:364

Shortcodes 1

[breaking-news-wp] breaking-news.php:91
WordPress Hooks 5
actionplugins_loadedbreaking-news.php:25
actionwp_enqueue_scriptsbreaking-news.php:33
actionadmin_enqueue_scriptsbreaking-news.php:39
actionadmin_menubreaking-news.php:97
actionadmin_initbreaking-news.php:151
Maintenance & Trust

Breaking News WP Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 29, 2019
PHP min version7.1.16
Downloads13K

Community Trust

Rating80/100
Number of ratings4
Active installs400
Developer Profile

Breaking News WP Developer Profile

doit

3 plugins · 1K total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Breaking News WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/breaking-news-wp/js/jquery.marquee.min.js/wp-content/plugins/breaking-news-wp/js/marquee-scroll-min.js/wp-content/plugins/breaking-news-wp/js/marquee-scroll.js
Script Paths
/wp-content/plugins/breaking-news-wp/js/bn-opt-res.js/wp-content/plugins/breaking-news-wp/js/jquery.marquee.min.js/wp-content/plugins/breaking-news-wp/js/marquee-scroll-min.js/wp-content/plugins/breaking-news-wp/js/marquee-scroll.js

HTML / DOM Fingerprints

CSS Classes
brnwp_custom_text
Data Attributes
name="brnwp_theme"id="brnwp_theme_one"id="brnwp_theme_two"id="brnwp_dim_barra"id="brnwp_testo_pers"id="brnwp_text"+1 more
JS Globals
brnwp_ajax_sdbrnwp_custom_text_check
Shortcode Output
[breaking-news-wp]
FAQ

Frequently Asked Questions about Breaking News WP