CVE-2014-125130

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-02: 210-02
Referenced assets1 URL
Full discourse2 posts
  • The Circuitry@thecircuitry_

    Breaking today: NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin. We tracked 203 stories and kept the 3 that matter — your two-minute, verified Rundown. https://t.co/8GEhNooCMi

    0000021
    36 followersView on X
  • The Circuitry@thecircuitry_

    CVE-2014-125130 assigned to CodeArt Google MP3 plugin: • CVSS 7.5 high • Path traversal via direct_download.php • Unauthenticated wp-config.php access Exploitation first seen 2023-10-19. https://thecircuitry.to/article/nvd-adds-cve-2014-125130-for-codeart-google-mp3-wordpress-plugin-murd43s4

    0000023
    36 followersView on X

Explore more