CVE-2014-8799

NUCLEI

DukaPress <2.5.4 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

Exploits (2)

exploitdb WORKING POC
by Kacper Szurek · textwebappsphp
https://www.exploit-db.com/exploits/35346
metasploit WORKING POC
by Kacper Szurek · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_dukapress_file_read.rb

Nuclei Templates (1)

WordPress Plugin DukaPress 2.5.2 - Directory Traversal
MEDIUMby daffainfo

Scores

EPSS 0.9113
EPSS Percentile 99.7%

Details

CWE
CWE-22
Status published
Products (1)
dukapress/dukapress < 2.5.3
Published Nov 28, 2014
Tracked Since Feb 18, 2026