CVE-2019-14205: Nevma Adaptive Images

High severity, CVSS 7.5. EPSS: 63.4% chance of exploitation in the next 30 days.

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

Affected products

  • Nevma Adaptive Images: before 0.6.67 (fixed in 0.6.67)

Published 2019-07-21. Last modified 2026-06-17.