CVE-2019-14206 is a path traversal issue in the Nevma Adaptive Images (Adaptive Images) WordPress plugin (reported as affecting versions prior to 0.6.67) where the plugin’s adaptive-images-script.php processes attacker-controlled request parameters (notably $REQUEST['adaptive-images-settings'] and sub-keys such as adaptive-images-settings[source_file]) without sufficient validation/sanitization. This unsafe path construction can be abused via crafted HTTP requests to traverse directories and target arbitrary filesystem paths, enabling unauthorized file operations including arbitrary file deletion; the provided supporting material also demonstrates arbitrary file read (e.g., retrieving /etc/passwd) by manipulating adaptive-images-settings[source_file].
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive proof-of-concept (PoC) and test environment for CVE-2019-14206, a critical arbitrary file deletion vulnerability in the Adaptive Images for WordPress plugin (versions < 0.6.67). The exploit leverages unsanitized user input in the 'adaptive-images-settings' request parameter, allowing an attacker to manipulate file paths and trigger the deletion of arbitrary files on the server, such as wp-config.php. The attack is unauthenticated and can be performed remotely via crafted HTTP GET requests to the adaptive-images-script.php endpoint. The repository includes: - Multiple PoC scripts in PHP, Bash, and Python to demonstrate and automate the exploit. - Docker-based and local test environments for safe reproduction. - Example payloads and detailed documentation (README.md, README-POC.md, QUICKSTART.md) explaining the vulnerability, exploitation steps, and mitigation. - Simulated vulnerable plugin code and test files, including a vulnerable version of adaptive-images-script.php and test WordPress configuration files. - Nuclei template references for automated detection. The exploit's main capability is the deletion of arbitrary files, which can lead to denial of service and further compromise (e.g., LFI or RCE). The main fingerprintable endpoint is /wp-content/plugins/adaptive-images/adaptive-images-script.php, and the primary target file is wp-config.php. The code is operational and can be used to confirm the vulnerability in test or real environments (with permission).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CVE-2019-14206 is a vulnerability in the Nevma Adaptive Images WordPress plugin that allows for arbitrary file deletion via path traversal. This can be exploited by manipulating plugin parameters to delete files on the server, potentially leading to denial of service or further compromise.
A vulnerability in the Adaptive Images for WordPress plugin (version 0.6.66) that allows local file inclusion (LFI), remote code execution (RCE), and file deletion via crafted requests.
A directory traversal vulnerability in the Adaptive Images WordPress plugin allows remote attackers to read arbitrary files from the server, such as /etc/passwd, by manipulating the 'adaptive-images-settings[source_file]' parameter.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.