Unauthenticated Arbitrary File Read in Google MP3 Audio Player Plugin
The CodeArt Google MP3 Audio Player plugin for WordPress contains an unauthenticated path-traversal vulnerability in direct_download.php that allows remote attackers to read sensitive configuration files.
CVE search metadata
CVE search record: CVE-2014-125130. Severity: high. CVSS: 7.5. KEV: no. Product: Google MP3 Audio Player (<= 1.0.11). Brief: Unauthenticated Arbitrary File Read in Google MP3 Audio Player Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-google-mp3-plugin-traversal/
The CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress, in versions through 1.0.11, is susceptible to an unauthenticated arbitrary file read vulnerability. The flaw exists within the direct_download.php script, which fails to properly sanitize user-supplied input provided via the file parameter. By crafting a request containing path-traversal sequences, a remote, unauthenticated attacker can escape the intended directory and access arbitrary files on the underlying web server.
This vulnerability is particularly critical because it allows for the retrieval of wp-config.php, which typically contains sensitive database credentials, authentication unique keys, and salts. Access to these files provides the attacker with the necessary information to gain deeper access to the WordPress environment or potentially perform remote code execution if the database is accessible. Active exploitation of this vulnerability has been observed since October 2023, as reported by the Shadowserver Foundation.
Impact
Successful exploitation allows an unauthenticated attacker to read arbitrary files from the server's file system. This often leads to the compromise of the wp-config.php file, resulting in the exposure of database credentials and cryptographic secrets. An attacker possessing these credentials can gain full administrative control over the WordPress application, leading to complete site compromise, data theft, or the installation of malicious persistent backdoors.
Recommendation
- Patch immediately by updating the Google MP3 Audio Player plugin to a version beyond 1.0.11, if available.
- If an update is not available, remove the plugin entirely or restrict access to
direct_download.phpat the web server level. - Deploy the provided Sigma rule to detect attempts to access
direct_download.phpwith path-traversal sequences in thefileparameter. - Audit server logs for requests containing suspicious sequences like
../directed at this plugin endpoint.
Immediate actions
Review web server logs for requests targeting direct_download.php with path traversal characters.
Mitigations
Disable or remove the Google MP3 Audio Player plugin until an update is available.
CVE-2014-125130
Detection coverage 1
Detect CVE-2014-125130 Exploitation - Path Traversal in direct_download.php
highDetects exploitation attempts against CVE-2014-125130 by identifying path traversal sequences in requests to direct_download.php.
Detection queries are available on the platform. Get full rules →