CVE-2014-4937

BookX plugin 1.7 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Anant Shrivastava · textwebappsphp
https://www.exploit-db.com/exploits/39251

References (1)

Core 1

Scores

EPSS 0.0596
EPSS Percentile 90.7%

Details

CWE
CWE-22
Status published
Products (1)
bookx_plugin_project/bookx 1.7
Published Jul 11, 2014
Tracked Since Feb 18, 2026