CVE-2019-14206: Nevma Adaptive Images

High severity, CVSS 7.5. EPSS: 4.7% chance of exploitation in the next 30 days.

An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.

Affected products

  • Nevma Adaptive Images: before 0.6.67 (fixed in 0.6.67)

Published 2019-07-21. Last modified 2026-06-17.