Skip to content
Urgent CVE-2014-125130: File Disclosure in CodeArt Google MP3 Player Plugin

Urgent CVE-2014-125130: File Disclosure in CodeArt Google MP3 Player Plugin

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2014-125130 allows unauthenticated file read vulnerabilities in the plugin.
  • •Attackers can exploit this to access sensitive configuration files.
  • •Immediate updates or plugin removal is critical for affected WordPress sites.

The CodeArt Google MP3 Audio Player plugin for WordPress, up to version 1.0.11, has an unauthenticated arbitrary file read vulnerability (CVE-2014-125130), allowing attackers to exploit path traversal in direct_download.php. This vulnerability was first observed being exploited on October 19, 2023, enabling unauthorized access to sensitive files like wp-config.php, which can lead to full site compromise. Public WordPress sites using this plugin are at the highest risk, especially those that are outdated or neglected. Immediate action is required to mitigate risks, including updating to version 1.0.12 or later, or disabling the plugin entirely. The vulnerability has a CVSS score of 8.7, indicating high severity, and is currently listed as. Security professionals should audit their logs for suspicious access and rotate any exposed credentials.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-10-19
Exploitation observed
The Shadowserver Foundation reported first evidence of exploitation of the vulnerability.
Redpacketsecurity
2026-10-02
CVE-2014-125130 published
CVE-2014-125130 was published with a CVSS score of 8.7, indicating high severity.
Redpacketsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2014-125130 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of the plugin are vulnerable?
Versions of the CodeArt Google MP3 Audio Player plugin up to 1.0.11 are vulnerable.
What should I do if I can't update the plugin?
If you cannot update, disable the plugin or block access to the vulnerable endpoint immediately.
Is there evidence of active exploitation?
Yes, exploitation was first observed on October 19, 2023, according to the Shadowserver Foundation.