Ads Pro Plugin Local File Inclusion Vulnerability Leading to Remote Code Execution
Vulnerability
A local file inclusion vulnerability allowing remote code execution has been identified in the Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager, affecting all versions through 4.89. This vulnerability arises from a combination of SQL injection and local file inclusion flaws, which can be exploited by unauthenticated attackers. The exploitation involves uploading a malicious image file that is later retrieved through the SQL injection vulnerability and executed as PHP code via the local file inclusion vulnerability.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where the affected WordPress site is hosted.
Remediation
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
