CVE-2014-5187: Tom m8te Plugin Project Tom-m8te Plugin

Medium severity, CVSS 5.0. EPSS: 4.7% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

Affected products

Published 2014-08-06. Last modified 2026-06-17.