S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2014-4940 Scanner

Detects 'Directory Traversal' vulnerability in Tera Charts plugin for Wordpress affects v. 0.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2014-4940
5.0
CVSS

Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Tera Charts plugin is a tool used for WordPress websites to display interactive visualizations of data. This plugin is a highly-rated graphing and charting tool that is often used for displaying data in an easy-to-understand format. Tera Charts is widely used in various industries, including finance, health care, and marketing.

The CVE-2014-4940 vulnerability is a multiple directory traversal flaw that exists in Tera Charts plugin version 0.1 for WordPress. This vulnerability enables remote attackers to read arbitrary files through the "fn" parameter in the "charts/treemap.php" or "charts/zoomabletreemap.php" directory. Directory traversal attacks are possible when an application doesn't sanitize input correctly, allowing an attacker to traverse the file system and be granted access to sensitive files.

The exploitation of this vulnerability can potentially lead to severe consequences. Cybercriminals could extract sensitive data, such as passwords and login credentials, from compromised files. Attackers can also use the compromised system to deliver malware payloads or steal confidential information, putting both the organization and their customers at risk. Moreover, the exploitation of this vulnerability can negatively impact the organization's reputation, possibly leading to financial damage.

In conclusion, security is a crucial aspect of every business that operates in the digital space. With the pro features of s4e.io, you can quickly identify and remediate vulnerabilities in your digital assets, including your websites and web applications. Securityforall.com offers various features, including machine learning-based vulnerability assessments, a web application firewall, and a robust vulnerability management system to help you stay ahead of the curve and protect your digital assets. By using these advanced security tools and practices, you can significantly reduce the risk of cyberattacks and data breaches.

 

REFERENCES

Solution Advice

Various precautions can be taken to protect against this vulnerability, including:

  • Updating the Tera Charts plugin to the latest version
  • Implementing web application firewalls (WAFs)
  • Implementing server-side input data validation
  • Restricting access to sensitive files and directories
  • Implementing access control and authentication mechanisms

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-4940 scanner - Directory Traversal vulnerability in Tera Charts plugin for Wordpress | S4E