Junglewise Threat Intelligence

CVE-2019-25727: Web-Dorado Ad Manager WD arbitrary file download in edit.php

CVE-2019-25727 · Severity: critical · CVSS 9.8 · Published 2026-06-04

Executive brief

Ad Manager WD is a WordPress plugin used to manage advertisements on websites. A security flaw in this plugin allows an unauthorized person to download sensitive files directly from the web server. This could lead to the exposure of database credentials, configuration files, and other private data, potentially allowing a full takeover of the website.

Technical details

A path traversal vulnerability (CWE-22) exists in the Ad Manager WD plugin for WordPress through version 1.0.11. The flaw is located in the 'wd_ads_admin_class.php' file, where the 'path' GET parameter is passed directly to the 'readfile()' function without adequate sanitization when the 'export' parameter is set to 'export_csv'. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request to the 'edit.php' endpoint. This allows the attacker to read and download arbitrary files from the server, such as 'wp-config.php', which contains sensitive database credentials and encryption keys.

Affected products

  • Web-Dorado Ad Manager WD <= 1.0.11

Timeline

  • 2019-01-25: disclosed: Initial discovery and exploit development by researcher
  • 2019-01-28: other: Exploit published on Exploit-DB
  • 2026-06-04: advisory: CVE published and NVD record created

References