{"id":"CVE-2014-125130","title":"CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-trav…","summary":"CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-trav…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"Damjan","product":"CodeArt Google MP3 Audio Player","affected":["codeart_google_mp3_audio_player <= 1.0.11"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T19:16:37.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2014-125130","references":[{"url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wp-googlemp3-lfi.yaml","label":"disclosure@vulncheck.com"},{"url":"https://patchstack.com/database/wordpress/plugin/google-mp3-audio-player/vulnerability/wordpress-codeart-google-mp3-player-plugin-file-disclosure-download","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/35460","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/codeart-google-mp3-audio-player-arbitrary-file-read-via-direct-download-php","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T22:33:09.840Z","slug":"CVE-2014-125130","body":"## Overview\n\nCodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}