Unrated severityNVD Advisory· Published Sep 3, 2014· Updated May 6, 2026
CVE-2014-5465
CVE-2014-5465
Description
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Affected products
4cpe:2.3:a:werdswords:download_shortcode:0.1:*:*:*:*:wordpress:*:*+ 3 more
- cpe:2.3:a:werdswords:download_shortcode:0.1:*:*:*:*:wordpress:*:*
- cpe:2.3:a:werdswords:download_shortcode:0.2.2:*:*:*:*:wordpress:*:*
- cpe:2.3:a:werdswords:download_shortcode:0.2:*:*:*:*:wordpress:*:*
- cpe:2.3:a:werdswords:download_shortcode:*:*:*:*:*:wordpress:*:*range: <=0.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- wordpress.org/plugins/download-shortcode/changelog/nvdPatch
- wordpress.org/support/topic/plugin-download-shortcode-security-issuenvdPatchVendor Advisory
- wordpress.org/support/topic/vulnerability-5nvdPatch
- packetstormsecurity.com/files/128024/WordPress-ShortCode-1.1-Local-File-Inclusion.htmlnvdExploit
- www.exploit-db.com/exploits/34436nvdExploit
- www.securityfocus.com/bid/69440nvdExploit
News mentions
0No linked articles in our index yet.