According to this advisory on the FrSIRT website, users of the P-News package have two somethings to worry about - a file upload and remote information disclosure vulnerability.
Multiple vulnerabilities have been identified in P-News, which could be exploited by remote attackers to compromise a vulnerable server or disclose sensitive information.
The file upload issue has to do with the ability to upload an Avatar to the system that doesn't validate the file extension and the second is a design flaw for the location of the user information (a text file) inside the document root.
Unfortunately, so official patch has been supplied at this time, but a few quick edits to the code can make these issues go away.