Arbitrary File Download in WordPress Plugin Ad Manager WD by Web-Dorado
CVE-2019-25727
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 4 June 2026
Badges
What is CVE-2019-25727?
The Ad Manager WD plugin for WordPress version 1.0.11 contains a vulnerability that allows unauthenticated attackers to download sensitive files from the server. By sending specially crafted GET requests to the edit.php endpoint with an altered path parameter, attackers can access confidential files, such as wp-config.php, which could expose critical information to malicious entities. It is crucial for users of this plugin to implement immediate security measures to protect their WordPress installations.
Affected Version(s)
Ad Manager WD 1.0.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved