Description
WordPress Plugin Ad Manager by WD-Advanced Ad Manager is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file download vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Ad Manager by WD-Advanced Ad Manager version 1.0.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.13 or latest
References
https://www.exploit-db.com/exploits/46252
https://plugins.svn.wordpress.org/ad-manager-wd/trunk/readme.txt
Related Vulnerabilities
Roundcube Unspesificed Vulnerability (CVE-2018-9846)
Internet Information Services Other Vulnerability (CVE-2003-0223)
WordPress Plugin SpiderCatalog Unspecified Vulnerability (1.6.8)
WordPress Plugin Google XML Sitemap for Videos Cross-Site Request Forgery (2.6.1)
Jboss EAP 7PK - Security Features Vulnerability (CVE-2015-5178)