CVE-2014-125130
published 2026-10-02CVE-2014-125130: CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability…
PriorityP180high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.53%
43.1th percentile
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| damjan | codeart_google_mp3_audio_player | <= 1.0.11 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google MP3 Audio Player Plugin up to 1.0.11 direct_download.php file information disclosure
vuldb·2026-10-02·CVSS 7.5
CVE-2014-125130 [HIGH] Google MP3 Audio Player Plugin up to 1.0.11 direct_download.php file information disclosure
A vulnerability was found in Google MP3 Audio Player Plugin up to 1.0.11. It has been classified as problematic. This affects an unknown function of the file direct_download.php. The manipulation of the argument File leads to information disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2014-125130. The attack can be initiated remotely. Additionally, an exploit exists.
GHSA
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sen
ghsa_unreviewed·2026-10-02
CVE-2014-125130 [HIGH] CWE-22 CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sen
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
VulnCheck
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2014·CVSS 7.5
CVE-2014-125130 [HIGH] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavail
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wp-googlemp3-lfi.yamlhttps://patchstack.com/database/wordpress/plugin/google-mp3-audio-player/vulnerability/wordpress-codeart-google-mp3-player-plugin-file-disclosure-downloadhttps://www.exploit-db.com/exploits/35460https://www.vulncheck.com/advisories/codeart-google-mp3-audio-player-arbitrary-file-read-via-direct-download-php
2026-10-02
Published
Exploited in the wild