Skip to content
Security & Trust

WordPress MP3 plugin flaw: exploitation seen in 2023, NVD entry in 2026

CVE-2014-125130 exposes wp-config.php to anyone. In our reading, its score understates what that file unlocks.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
WordPress MP3 plugin flaw: exploitation seen in 2023, NVD entry in 2026

AI-generated image for WebPulse. About our images

In brief
  • NIST's database published CVE-2014-125130 on October 2, 2026, for a WordPress audio plugin that lets anyone read wp-config.php. The Shadowserver Foundation first saw exploitation in October 2023.
  • That file holds database credentials and secret keys. The NVD text says exposure leads to full site compromise; in our reading, a score for a file read understates the risk.
  • Check for the google-mp3-audio-player plugin, search logs for direct_download.php requests containing "../", and change the wp-config.php credentials if exposure is possible.

A security record is a lagging indicator. It tells you what a database has caught up on, not when the risk began. One new NVD entry shows this clearly. It is also a reminder of what a single configuration file holds.

What the record says

NIST's National Vulnerability Database published CVE-2014-125130 on October 2, 2026. It covers the CodeArt Google MP3 Audio Player plugin for WordPress, versions through 1.0.11. The plugin's slug is google-mp3-audio-player.

The flaw lets a remote attacker read files from the server without logging in. The record describes the Shadowserver Foundation first observing exploitation evidence on October 19, 2023. That is almost three years before the NVD entry appeared.

2023-10-19
Earliest exploitation evidence
Source: NIST NVD record CVE-2014-125130, citing the Shadowserver Foundation (published 2026-10-02)

How the flaw works

The plugin includes a script called direct_download.php. It takes a file name in a parameter called "file". It does not check that the name stays inside the plugin's own folder.

That gap is called path traversal. The sequence "../" means "go up one folder". An attacker who sends "../../wp-config.php" walks out of the plugin folder and asks for the site's main configuration file. The server hands it over.

No account is needed. The record lists the attack as network-reachable, low complexity and requiring no privileges or user interaction.

Why the score may understate the damage

NVD lists a CVSS 3.1 base score of 7.5 (High). It lists a CVSS 4.0 score of 8.7 (High). Both were assigned by [email protected].

7.5 (High)
CVSS 3.1 base score
Source: NIST NVD, scored by [email protected] (2026-10-02)
8.7 (High)
CVSS 4.0 base score
Source: NIST NVD, scored by [email protected] (2026-10-02)

Look at the vector, though. Confidentiality impact is High. Integrity and availability impact are both None. The score rates the act of reading a file. It does not rate what is inside the file.

The NVD text says wp-config.php contains database credentials and secret keys. It says exposure leads to full site compromise. A file read that the score treats as a leak can become a takeover.

This is our interpretation, not a finding from the record. Severity scores measure the first step of an attack. They do not measure the chain that follows. A leaked password file is a key, not just a secret.

The questions this raises

The record does not say whether a fixed version exists. It lists the affected range as through 1.0.11. A team cannot assume an update will solve this.

The record also does not say how many sites run the plugin. We do not know how many were affected. WebPulse does not detect individual WordPress plugins, so we cannot estimate it.

What the record does show is the gap itself. Exploitation was observed in 2023. The NVD entry dates from 2026. A team that waited for its scanner to flag this CVE could have learned of it years after exploitation was first observed.

Note that the NVD references include a Nuclei detection template, an Exploit-DB entry, a Patchstack database page and a VulnCheck advisory. Public detail on this flaw exists outside NVD. Your tooling needs to pull from more than one list.

What to ask your team

First, ask whether google-mp3-audio-player is installed on any site the company runs, including old marketing sites and agency-managed pages. If yes, ask whether it is needed. If the record names no fix for your version, removal is the safer default.

Second, ask for a search of web server logs for requests to direct_download.php that contain "../". Any hit means wp-config.php may have been read.

Third, if there is any sign of exposure, ask for the database password and the secret keys in wp-config.php to be changed. Changing them is how you take the stolen key away.

Fourth, ask where the plugin inventory comes from. If it relies on one vulnerability feed, you inherit that feed's delay.

The lesson is simple. A vulnerability has a date when it was found, a date when it was used and a date when it was recorded. Your risk follows the first two. Your tools often follow the third.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.

Share this insight