← WordPress Vulnerabilities
WordPress security by component

Adning Advertising

Adning Advertising is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 07, 2023; the highest published CVSS base score is 9.8.

Plugin slug: adning-advertising

CVE-2020-36728: Adning Advertising: Filesystem traversal

Adning Advertising is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 07, 2023
Safe version guidanceSee mitigation notes
Published vulnerabilities for adning-advertising
Safe version
Jun 07, 2023 CVE-2020-36728
Adning Advertising: Filesystem traversal
Adning Advertising is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVD9.8
Jun 07, 2023 CVE-2020-36705
Adning Advertising: Dangerous file upload
Adning Advertising is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVD9.8