
Breaking today: NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin. We tracked 203 stories and kept the 3 that matter — your two-minute, verified Rundown. https://t.co/8GEhNooCMi
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

Breaking today: NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin. We tracked 203 stories and kept the 3 that matter — your two-minute, verified Rundown. https://t.co/8GEhNooCMi

CVE-2014-125130 assigned to CodeArt Google MP3 plugin: • CVSS 7.5 high • Path traversal via direct_download.php • Unauthenticated wp-config.php access Exploitation first seen 2023-10-19. https://thecircuitry.to/article/nvd-adds-cve-2014-125130-for-codeart-google-mp3-wordpress-plugin-murd43s4