CVE-2015-2825

Simple Ads Manager < 2.5.94 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path parameter.

Exploits (1)

exploitdb WORKING POC
by ITAS Team · textwebappsphp
https://www.exploit-db.com/exploits/36614

Scores

EPSS 0.3526
EPSS Percentile 97.1%

Details

Status published
Products (1)
simple_ads_manager_project/simple_ads_manager < 2.5.94
Published Apr 21, 2015
Tracked Since Feb 18, 2026