Description
WordPress Plugin WordPress Ad Widget is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WordPress Ad Widget version 2.11.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.12.0 or latest
References
http://seclists.org/fulldisclosure/2017/Oct/17
https://packetstormsecurity.com/files/144553/WordPress-Ad-Widget-2.10.0-Local-File-Inclusion.html
https://plugins.trac.wordpress.org/changeset/1628751/ad-widget
Related Vulnerabilities
WordPress Plugin WP eCommerce 'wpsc-transaction_results_functions.php' SQL Injection (3.8.7.5)
WordPress Plugin Participants Database SQL Injection (1.5.4.8)
WordPress Plugin Integration for Contact Form 7 and Zoho Cross-Site Scripting (1.1.7)
WordPress Plugin BigBlueButton Cross-Site Scripting (2.2.3)
WordPress Plugin Metronet Tag Manager Cross-Site Request Forgery (1.2.7)