Description
WordPress Plugin WordPress Ad Widget is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WordPress Ad Widget version 2.11.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.12.0 or latest
References
http://seclists.org/fulldisclosure/2017/Oct/17
https://packetstormsecurity.com/files/144553/WordPress-Ad-Widget-2.10.0-Local-File-Inclusion.html
https://plugins.trac.wordpress.org/changeset/1628751/ad-widget
Related Vulnerabilities
Oracle HTTP Server CVE-2006-0435 Vulnerability (CVE-2006-0435)
WordPress Plugin Complianz-GDPR/CCPA Cookie Consent SQL Injection (6.3.3)
WordPress Plugin WP Web Scraper Unspecified Vulnerability (2.4)
WebLogic CVE-2022-21347 Vulnerability (CVE-2022-21347)
WordPress Plugin The Plus Addons for Elementor Cross-Site Scripting (4.1.11)