{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/codeart/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:codeart:google_mp3_audio_player:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2014-125130"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Google MP3 Audio Player (\u003c= 1.0.11)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","path-traversal","arbitrary-file-read"],"_cs_type":"threat","_cs_vendors":["CodeArt"],"content_html":"\u003cp\u003eThe CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress, in versions through 1.0.11, is susceptible to an unauthenticated arbitrary file read vulnerability. The flaw exists within the \u003ccode\u003edirect_download.php\u003c/code\u003e script, which fails to properly sanitize user-supplied input provided via the \u003ccode\u003efile\u003c/code\u003e parameter. By crafting a request containing path-traversal sequences, a remote, unauthenticated attacker can escape the intended directory and access arbitrary files on the underlying web server.\u003c/p\u003e\n\u003cp\u003eThis vulnerability is particularly critical because it allows for the retrieval of \u003ccode\u003ewp-config.php\u003c/code\u003e, which typically contains sensitive database credentials, authentication unique keys, and salts. Access to these files provides the attacker with the necessary information to gain deeper access to the WordPress environment or potentially perform remote code execution if the database is accessible. Active exploitation of this vulnerability has been observed since October 2023, as reported by the Shadowserver Foundation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to read arbitrary files from the server's file system. This often leads to the compromise of the \u003ccode\u003ewp-config.php\u003c/code\u003e file, resulting in the exposure of database credentials and cryptographic secrets. An attacker possessing these credentials can gain full administrative control over the WordPress application, leading to complete site compromise, data theft, or the installation of malicious persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by updating the Google MP3 Audio Player plugin to a version beyond 1.0.11, if available.\u003c/li\u003e\n\u003cli\u003eIf an update is not available, remove the plugin entirely or restrict access to \u003ccode\u003edirect_download.php\u003c/code\u003e at the web server level.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to access \u003ccode\u003edirect_download.php\u003c/code\u003e with path-traversal sequences in the \u003ccode\u003efile\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eAudit server logs for requests containing suspicious sequences like \u003ccode\u003e../\u003c/code\u003e directed at this plugin endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T20:26:38Z","date_published":"2026-10-02T20:26:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-google-mp3-plugin-traversal/","summary":"The CodeArt Google MP3 Audio Player plugin for WordPress contains an unauthenticated path-traversal vulnerability in direct_download.php that allows remote attackers to read sensitive configuration files.","title":"Unauthenticated Arbitrary File Read in Google MP3 Audio Player Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-google-mp3-plugin-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - CodeArt","version":"https://jsonfeed.org/version/1.1"}