nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25727 CVE-2019-25727
CRITICAL
WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download
Record summary
CVE-2019-25727 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ad Manager WDBrowse ad-manager-wd / Ad Manager WD | CVE List | 1.0.11 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File DownloadExploitDB exploitby 41!kh4224rDzNot analyzed1 file
References
4Official Product Homepageproduct
https://web-dorado.com/products/wordpress-ad-manager-wd.html ExploitDB-46252exploit
https://www.exploit-db.com/exploits/46252 VulnCheck Advisory: WordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-ad-manager-wd-arbitrary-file-download