CVE-2014-8799
NUCLEIDukaPress <2.5.4 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
Exploits (2)
metasploit
WORKING POC
by Kacper Szurek · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_dukapress_file_read.rb
Nuclei Templates (1)
WordPress Plugin DukaPress 2.5.2 - Directory Traversal
MEDIUMby daffainfo
References (5)
Scores
EPSS
0.9113
EPSS Percentile
99.7%
Details
CWE
CWE-22
Status
published
Products (1)
dukapress/dukapress
< 2.5.3
Published
Nov 28, 2014
Tracked Since
Feb 18, 2026