CVE-2014-125130: CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of directdownload.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
Affected Software
Event History
Frequently Asked Questions
Which plugin versions should be treated as affected?
CodeArt Google MP3 Audio Player versions through 1.0.11 are affected.
Has exploitation been observed in the wild?
Yes. The Shadowserver Foundation first observed exploitation evidence on 2023-10-19.
What information could an unauthenticated attacker obtain?
An attacker can use a path-traversal payload in the file parameter of direct_download.php to retrieve files such as wp-config.php. That file may contain database credentials and WordPress secret keys, which can lead to full site compromise.