---
id: CVE-2014-125130
title: >-
  CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress
  through 1.0.11 contains an unauthenticated arbitrary file read vulnerability
  that allows remote attackers to retrieve sensitive files by supplying a
  path-trav…
summary: >-
  CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress
  through 1.0.11 contains an unauthenticated arbitrary file read vulnerability
  that allows remote attackers to retrieve sensitive files by supplying a
  path-trav…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: Damjan
product: CodeArt Google MP3 Audio Player
affected:
  - codeart_google_mp3_audio_player <= 1.0.11
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T19:16:37.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2014-125130'
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wp-googlemp3-lfi.yaml
    label: disclosure@vulncheck.com
  - url: >-
      https://patchstack.com/database/wordpress/plugin/google-mp3-audio-player/vulnerability/wordpress-codeart-google-mp3-player-plugin-file-disclosure-download
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/35460'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/codeart-google-mp3-audio-player-arbitrary-file-read-via-direct-download-php
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T22:33:09.840Z'
---

## Overview

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
