CVE

CVE-2015-1579 — Slider Revolution [revslider] < 4.1.5 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-1579 Slider Revolution [revslider] < 4.1.5 (unfixed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 4.1.5 4.1.5 2015-02-11

CVE-2015-1579

The Slider Revolution plugin (revslider) before version 4.1.5 contains a directory traversal flaw that enables attackers to access arbitrary files on the server. By inserting dot-dot sequences into the img parameter when making requests to the revslider_show_image action via wp-admin/admin-ajax.php, an unauthenticated remote attacker can read sensitive files outside the intended directory. This vulnerability remains unfixed in the affected versions and may overlap with a previously reported issue tracked as CVE-2014-9734.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.