Description
WordPress Plugin Simple Ads Manager is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Simple Ads Manager version 2.10.0.130 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
Moodle Improper Privilege Management Vulnerability (CVE-2017-7532)
WordPress 4.6.x Cross-Domain Flash Injection Vulnerability (4.6 - 4.6.9)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1133)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.23)