CVE-2019-25727 CRITICAL

CVE-2019-25727: WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download

Vendor Ad-Manager-Wd
Product Ad Manager WD
Weakness CWE-22 · Path traversal
Published June 4, 2026
Last update June 4, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

Description

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server.

Key dates

Disclosure timeline

June 4, 2026 CVE published
June 4, 2026 Record updated