Impact
The Ad Manager WD plugin contains an arbitrary file download vulnerability that is triggered by manipulating the path parameter in the edit.php endpoint. An unauthenticated attacker can send a GET request that forces the server to return any file it can access, such as wp-config.php. This results in a serious confidentiality breach that can expose database credentials and other sensitive information, potentially enabling further attacks. The flaw is a Directory Traversal issue (CWE‑22).
Affected Systems
WordPress sites that have the Ad Manager WD plugin version 1.0.11 installed are affected; sites using other versions or without the plugin are not impacted according to the available data.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity vulnerability. Because the flaw is exploitable without authentication via a simple HTTP GET request, the attack surface is large and the likelihood of exploitation is high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of a KEV listing does not reduce the risk. Attackers can reach the vulnerable endpoint from any internet‑connected location, making exploitation trivial for those who can target the affected web servers.
OpenCVE Enrichment