CVE-2018-9118

HIGH EXPLOITED IN THE WILD NUCLEI

99robots WP Background Takeover Advertisements - Path Traversal

Title source: rule

Description

exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

Exploits (1)

exploitdb WORKING POC
by Colette Chamberland · textwebappsphp
https://www.exploit-db.com/exploits/44417

Nuclei Templates (1)

WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion
HIGHby 0x_Akoko

Scores

CVSS v3 7.5
EPSS 0.7131
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2021-04-12
InTheWild.io 2021-04-12
CWE
CWE-22
Status published
Products (1)
99robots/wp_background_takeover_advertisements < 4.1.5
Published Apr 12, 2018
Tracked Since Feb 18, 2026