CVE-2014-9734

EXPLOITED

Slider Revolution <4.2 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Hugo Santiago · textwebappsphp
https://www.exploit-db.com/exploits/34511
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/36554

Scores

EPSS 0.0518
EPSS Percentile 89.9%

Details

VulnCheck KEV 2014-09-03
CWE
CWE-22
Status published
Products (1)
themepunch/slider_revolution < 4.1.4
Published Jun 30, 2015
Tracked Since Feb 18, 2026