CVE-2019-14205
nevma adaptive_images Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-14205 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
adaptive_imagesBrowse nevma / adaptive_images | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Nevma Adaptive Images <0.6.67 - Local File InclusionCVSS 7.5
WordPress Nevma Adaptive Images plugin before 0.6.67 allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
Impact
An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to sensitive information disclosure or remote code execution.
Remediation
Update to the latest version of the plugin (0.6.67) or apply the patch provided by the vendor.
Source: ProjectDiscovery