patchstack.com Urgent CVE-2014-125130: File Disclosure in CodeArt Google MP3 Player Plugin
Article Content
- •CVE-2014-125130 allows unauthenticated file read vulnerabilities in the plugin.
- •Attackers can exploit this to access sensitive configuration files.
- •Immediate updates or plugin removal is critical for affected WordPress sites.
The CodeArt Google MP3 Audio Player plugin for WordPress, up to version 1.0.11, has an unauthenticated arbitrary file read vulnerability (CVE-2014-125130), allowing attackers to exploit path traversal in direct_download.php. This vulnerability was first observed being exploited on October 19, 2023, enabling unauthorized access to sensitive files like wp-config.php, which can lead to full site compromise. Public WordPress sites using this plugin are at the highest risk, especially those that are outdated or neglected. Immediate action is required to mitigate risks, including updating to version 1.0.12 or later, or disabling the plugin entirely. The vulnerability has a CVSS score of 8.7, indicating high severity, and is currently listed as. Security professionals should audit their logs for suspicious access and rotate any exposed credentials.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2014-125130 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of the plugin are vulnerable?
What should I do if I can't update the plugin?
Is there evidence of active exploitation?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…