Vulnerability Details CVE-2019-14205
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.68
EPSS Ranking 98.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-14205
-
cpe:2.3:a:nevma:adaptive_images:0.1
-
cpe:2.3:a:nevma:adaptive_images:0.2.01
-
cpe:2.3:a:nevma:adaptive_images:0.2.02
-
cpe:2.3:a:nevma:adaptive_images:0.2.03
-
cpe:2.3:a:nevma:adaptive_images:0.2.04
-
cpe:2.3:a:nevma:adaptive_images:0.2.05
-
cpe:2.3:a:nevma:adaptive_images:0.2.06
-
cpe:2.3:a:nevma:adaptive_images:0.2.08
-
cpe:2.3:a:nevma:adaptive_images:0.3.0
-
cpe:2.3:a:nevma:adaptive_images:0.3.01
-
cpe:2.3:a:nevma:adaptive_images:0.3.02
-
cpe:2.3:a:nevma:adaptive_images:0.3.03
-
cpe:2.3:a:nevma:adaptive_images:0.3.04
-
cpe:2.3:a:nevma:adaptive_images:0.3.5
-
cpe:2.3:a:nevma:adaptive_images:0.3.51
-
cpe:2.3:a:nevma:adaptive_images:0.3.52
-
cpe:2.3:a:nevma:adaptive_images:0.5.0
-
cpe:2.3:a:nevma:adaptive_images:0.5.1
-
cpe:2.3:a:nevma:adaptive_images:0.5.2
-
cpe:2.3:a:nevma:adaptive_images:0.6.0
-
cpe:2.3:a:nevma:adaptive_images:0.6.1
-
cpe:2.3:a:nevma:adaptive_images:0.6.2
-
cpe:2.3:a:nevma:adaptive_images:0.6.3
-
cpe:2.3:a:nevma:adaptive_images:0.6.4
-
cpe:2.3:a:nevma:adaptive_images:0.6.41
-
cpe:2.3:a:nevma:adaptive_images:0.6.42
-
cpe:2.3:a:nevma:adaptive_images:0.6.5
-
cpe:2.3:a:nevma:adaptive_images:0.6.51
-
cpe:2.3:a:nevma:adaptive_images:0.6.60
-
cpe:2.3:a:nevma:adaptive_images:0.6.61
-
cpe:2.3:a:nevma:adaptive_images:0.6.62
-
cpe:2.3:a:nevma:adaptive_images:0.6.63
-
cpe:2.3:a:nevma:adaptive_images:0.6.64
-
cpe:2.3:a:nevma:adaptive_images:0.6.65
-
cpe:2.3:a:nevma:adaptive_images:0.6.66