S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2014-5368 Scanner

Detects 'Directory Traversal' vulnerability in Content Source Control plugin for Wordpress affects v. 3.0.0 and earlier.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2014-5368
5.0
CVSS

Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Content Source Control plugin for Wordpress is a tool that offers version control management for websites. It is designed to allow multiple users to work on a website, while keeping track of changes, and who made them. Its purpose is to streamline content management and facilitate collaboration among website administrators. 

However, the plugin has a critical vulnerability, tracked under CVE-2014-5368. This vulnerability is a directory traversal exploit located within the downloadfiles/download.php file. This function allows attackers to read any file on the server that they have necessary permissions for. By adding "../../" to the beginning of the filename parameter in the download.php file, an attacker can access files outside of the plugin's intended directories. This exploit is available for exploitation in version 3.0.0 and earlier.

If this vulnerability is exploited successfully, the attacker can read sensitive information, and access personal data such as user accounts, financial records, and passwords. Moreover, an attacker can exploit this vulnerability to gain access to sensitive data for malicious activities such as blackmail and ransomware.

In conclusion, being aware of vulnerabilities and taking active measures to protect digital assets is a critical step in securing a website. s4e.io provides a comprehensive security solution that offers pro features to help identify, detect, and mitigate vulnerabilities in your digital assets. By leveraging this platform, website administrators can keep their websites safe and secure from potential attacks, and focus on their business operations with peace of mind.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including: 

  • Keeping the plugin updated to the latest version to patch the vulnerability. 
  • Limiting file permissions to only the necessary files and directories, preventing unauthorized access to sensitive information. 
  • Implementing a web application firewall that can detect and block directory traversal attacks. 
  • Monitoring website access logs for unusual activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-5368 scanner - Directory Traversal vulnerability in Content Source Control plugin for Wordpress | S4E