Unrated severityNVD Advisory· Published Nov 28, 2014· Updated May 6, 2026
CVE-2014-8801
CVE-2014-8801
Description
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.
Affected products
1- cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*Range: <1.7.15
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- packetstormsecurity.com/files/129189/Paid-Memberships-Pro-1.7.14.2-Path-Traversal.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/35303nvdExploitThird Party AdvisoryVDB Entry
- www.paidmembershipspro.com/2014/11/critical-security-update-pmpro-v1-7-15/nvdRelease NotesThird Party Advisory
- www.securityfocus.com/bid/71293nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/98805nvdThird Party AdvisoryVDB Entry
- wordpress.org/plugins/paid-memberships-pro/changelog/nvdRelease NotesThird Party Advisory
- security.szurek.pl/paid-memberships-pro-17142-path-traversal.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.