<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CodeArt - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/codeart/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:26:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/codeart/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary File Read in Google MP3 Audio Player Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-google-mp3-plugin-traversal/</link><pubDate>Fri, 02 Oct 2026 20:26:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-google-mp3-plugin-traversal/</guid><description>The CodeArt Google MP3 Audio Player plugin for WordPress contains an unauthenticated path-traversal vulnerability in direct_download.php that allows remote attackers to read sensitive configuration files.</description><content:encoded><![CDATA[<p>The CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress, in versions through 1.0.11, is susceptible to an unauthenticated arbitrary file read vulnerability. The flaw exists within the <code>direct_download.php</code> script, which fails to properly sanitize user-supplied input provided via the <code>file</code> parameter. By crafting a request containing path-traversal sequences, a remote, unauthenticated attacker can escape the intended directory and access arbitrary files on the underlying web server.</p>
<p>This vulnerability is particularly critical because it allows for the retrieval of <code>wp-config.php</code>, which typically contains sensitive database credentials, authentication unique keys, and salts. Access to these files provides the attacker with the necessary information to gain deeper access to the WordPress environment or potentially perform remote code execution if the database is accessible. Active exploitation of this vulnerability has been observed since October 2023, as reported by the Shadowserver Foundation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to read arbitrary files from the server's file system. This often leads to the compromise of the <code>wp-config.php</code> file, resulting in the exposure of database credentials and cryptographic secrets. An attacker possessing these credentials can gain full administrative control over the WordPress application, leading to complete site compromise, data theft, or the installation of malicious persistent backdoors.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by updating the Google MP3 Audio Player plugin to a version beyond 1.0.11, if available.</li>
<li>If an update is not available, remove the plugin entirely or restrict access to <code>direct_download.php</code> at the web server level.</li>
<li>Deploy the provided Sigma rule to detect attempts to access <code>direct_download.php</code> with path-traversal sequences in the <code>file</code> parameter.</li>
<li>Audit server logs for requests containing suspicious sequences like <code>../</code> directed at this plugin endpoint.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>wordpress</category><category>plugin</category><category>path-traversal</category><category>arbitrary-file-read</category></item></channel></rss>