GI-Media Library [gi-media-library] < 3.0 (closed)
unknown
[en] The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Jul 19, 2025
CVE-2015-10136 on NVD →
GI-Media Library < 3.0 - Directory Traversal
high
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Jan 15, 2015
CVE-2015-10136 on NVD →
GI-Media Library [gi-media-library] <= 2.2.2 (closed)
unknown
This plugin is prone to an arbitrary file download vulnerability.
Update the plugin.
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Jan 15, 2015
GI-Media Library [gi-media-library] < 3.0 (closed)
unknown
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Jan 15, 2015
GI-Media Library [gi-media-library] < 3.0 (closed)
unknown
The gi-media-library WordPress plugin was affected by an Arbitrary File Download security vulnerability.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database