Home

Description

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED Reserved 2025-07-18 | Published 2025-07-19 | Updated 2026-04-08 | Assigner Wordfence




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

Any version before 3.0
affected

Timeline

2015-01-15:Disclosed

References

www.wordfence.com/...-5148-42eb-9137-9c538184cda3?source=cve

wordpressa.quantika14.com/repository/index.php?id=24

github.com/...y/scanner/http/wp_gimedia_library_file_read.rb

wpscan.com/vulnerability/7754

wordpress.org/plugins/gi-media-library/

plugins.trac.wordpress.org/changeset/1132677

www.rapid7.com/...scanner/http/wp_gimedia_library_file_read/

cve.org (CVE-2015-10136)

nvd.nist.gov (CVE-2015-10136)

Download JSON