S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-14205 Scanner

CVE-2019-14205 scanner - Local File Inclusion vulnerability in Nevma Adaptive Images plugin for Wordpress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-14205
7.5
CVSS

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Nevma Adaptive Images is a plugin used in WordPress to adjust images according to the size of the device screen being used to view them. The purpose of this plugin is to enable websites to load images faster by reducing the size of images displayed on small screens and showing the original larger images on larger screens. The Nevma Adaptive Images plugin provides users with various features to customize how images are displayed on their website.

The Nevma Adaptive Images plugin experienced a vulnerability, CVE-2019-14205, which allowed remote attackers to retrieve arbitrary files through the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php. This means that attackers could access files and sensitive information deemed confidential and could use it for malicious purposes.

Exploiting this vulnerability can lead to various issues, including data loss, data breaches, and reputational damage. Attackers can access files containing sensitive data such as usernames and passwords, critical documents, and financial information. This data can be used to commit fraudulent activities and can result in financial and reputational losses for organizations.

The s4e.io platform offers pro features that can help individuals and organizations easily and quickly learn about vulnerabilities in their digital assets. By utilizing this platform, websites can detect and address vulnerabilities, implement anti-malware tools, and receive alerts about potential threats. It provides a secure and reliable solution to safeguarding digital assets from vulnerabilities such as CVE-2019-14205.

 

REFERENCES

Solution Advice

Protecting against this vulnerability requires implementing various precautions, including:

  • Ensuring that the latest version of the Nevma Adaptive Images plugin is installed
  • Removing old, unused plugins from the WordPress site
  • Filtering user input fields before processing any data
  • Implementing a web application firewall to detect and block malicious traffic
  • Using secure coding practices to limit the impact of any vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-14205 scanner - Local File Inclusion vulnerability in Nevma Adaptive Images plugin for Wordpress | S4E