Showing 1 vulnerability on this page for Ad Manager WD

Signals CISA KEV Ransomware Nuclei
ad-manager-wd vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server.

CWE-22Jun 4, 2026
CVSS9.3v4.0EPSS0.46%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX