CVE-2012-6651

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
31/07/2014
Last modified:
12/04/2025

Description

Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vitamin_plugin_project:vitamin:*:*:*:*:*:wordpress:*:* 1.0.0 (including)