Description
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 28 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elegantthemes
Elegantthemes divi |
|
| CPEs | cpe:2.3:a:elegantthemes:divi:-:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Elegant Themes
Elegant Themes divi |
Elegantthemes
Elegantthemes divi |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T04:47:17.035Z
Reserved: 2015-02-11T00:00:00.000Z
Link: CVE-2015-1579
No data.
Status : Modified
Published: 2015-02-11T19:59:06.417
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1579
No data.
OpenCVE Enrichment
No data.
Weaknesses