CVE-2014-5465

Werdswords Download Shortcode < 0.2.3 - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mehdi Karout & Christian Galeone · textwebappsphp
https://www.exploit-db.com/exploits/34436

References (6)

Core 6

Scores

EPSS 0.3279
EPSS Percentile 96.9%

Details

CWE
CWE-22
Status published
Products (4)
werdswords/download_shortcode 0.1
werdswords/download_shortcode 0.2
werdswords/download_shortcode 0.2.2
werdswords/download_shortcode < 0.2.3
Published Sep 03, 2014
Tracked Since Feb 18, 2026