CVE-2015-1579

EXPLOITED NUCLEI

Elegant Themes Divi - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-1579 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including Hugo Santiago, Claudio Viviani, paralelo14. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in multiple WordPress themes by leveraging a path traversal flaw in the 'revslider_show_image' action parameter. The PoC allows unauthorized access to sensitive files like 'wp-config.php'.

Description

Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Hugo Santiago · textwebappsphp
https://www.exploit-db.com/exploits/34511

This exploit demonstrates an arbitrary file download vulnerability in multiple WordPress themes by leveraging a path traversal flaw in the 'revslider_show_image' action parameter. The PoC allows unauthorized access to sensitive files like 'wp-config.php'.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress themes (CuckooTap, eShop, IncredibleWP, Ultimatum, Medicate, Centum, Avada, Striking, Beach Apollo)
No auth needed
Prerequisites: WordPress site with vulnerable theme installed · Access to the target's admin-ajax.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Claudio Viviani · textwebappsphp
https://www.exploit-db.com/exploits/36554

This exploit demonstrates an arbitrary file download vulnerability in WordPress Slider Revolution Responsive plugin versions <= 4.1.4. The PoC uses a path traversal technique via the 'img' parameter in the 'revslider_show_image' action to download sensitive files like 'wp-config.php'.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Slider Revolution Responsive <= 4.1.4
No auth needed
Prerequisites: WordPress installation with vulnerable Slider Revolution plugin · Access to the target's admin-ajax.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 28 stars
by paralelo14 · infoleak
https://github.com/paralelo14/WordPressMassExploiter

This is a mass exploiter for CVE-2015-1579, targeting WordPress sites with vulnerable RevSlider plugins. It uses Selenium to search Google for potential targets and attempts to download wp-config.php files via the vulnerability.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress with RevSlider plugin
No auth needed
Prerequisites: Selenium · BeautifulSoup · requests · Google search access
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by paralelo14 · remote
https://github.com/paralelo14/CVE-2015-1579

This is a functional exploit for CVE-2015-1579, targeting WordPress Slider Revolution Responsive <= 4.1.4. It performs an arbitrary file download (AFD) attack to retrieve the wp-config.php file by exploiting a path traversal vulnerability in the admin-ajax.php endpoint.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Slider Revolution Responsive <= 4.1.4
No auth needed
Prerequisites: Target must have the vulnerable Slider Revolution plugin installed and accessible · The admin-ajax.php endpoint must be reachable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress Slider Revolution - Local File Disclosure
MEDIUMby pussycat0x

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/7540
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36039

Scores

EPSS 0.8082
EPSS Percentile 99.2%

Details

VulnCheck KEV 2014-09-03
CWE
CWE-22
Status published
Products (1)
elegantthemes/divi
Published Feb 11, 2015
Tracked Since Feb 18, 2026