← Back to CVE List

CVE-2014-2674

Published: 2018-03-19T21:29Z
Last Modified: 2024-11-21T02:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt