Record summary

CVE-2019-14205 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Nevma Adaptive Images <0.6.67 - Local File InclusionCVSS 7.5

WordPress Nevma Adaptive Images plugin before 0.6.67 allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

Impact

An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to sensitive information disclosure or remote code execution.

Remediation

Update to the latest version of the plugin (0.6.67) or apply the patch provided by the vendor.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2019wordpresswp-pluginlfiwpnevmavkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nevma:adaptive_images:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5