markgruffer

2 exploits Active since Jul 2019
CVE-2019-14206 WRITEUP HIGH WRITEUP
Nevma Adaptive Images <0.6.67 - Privilege Escalation
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.
CVSS 7.5
CVE-2019-14205 WRITEUP HIGH WRITEUP
Nevma Adaptive Images <0.6.67 - Local File Inclusion
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
CVSS 7.5