plugin

Simple Ads Manager Vulnerabilities

18 known security issues reported for the Simple Ads Manager WordPress plugin. Most recent disclosed Sep 20, 2017.

3 critical 3 high 1 medium

Running Simple Ads Manager on your site? Check whether your installed version is affected.

Scan your site free

Simple Ads Manager [simple-ads-manager] >= 2.5.94 - <= 2.5.96

unknown

[en] WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.

Affected:
2.5.94 – 2.5.96
Fixed in:
2.5.96
Disclosed:
Sep 20, 2017

CVE-2015-2826 on NVD →

Simple Ads Manager <= 2.9.8.125 - Unauthenticated PHP Objection Injection

high

The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.8.125 via deserialization of untrusted input in the vulnerable function 'unserialize'. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. I...

CVSS:
8.3
Affected:
up to 2.10.0.130
Fixed in:
2.10.0.130
Disclosed:
Mar 17, 2017

Simple Ads Manager [simple-ads-manager] < 2.10.0.130

unknown

The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.8.125 via deserialization of untrusted input in the vulnerable function 'unserialize'. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. I...

Affected:
up to 2.10.0.130
Fixed in:
2.10.0.130
Disclosed:
Mar 17, 2017

SAM Pro (Free Edition) < 1.9.7.69 & Simple Ads Manager <= 2.10.0.130 & SAM Pro Lite < 1.9.0.53 - Local/Remote File Inclusion

high

The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7.68 via the 'wap' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to b...

CVSS:
8.8
Affected:
up to 2.10.0.130
Fix:
No patched version reported
Disclosed:
Oct 10, 2016

Simple Ads Manager [simple-ads-manager] <= 2.10.0.130 (unfixed)

unknown

The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7.68 via the 'wap' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to b...

Affected:
up to 2.10.0.130
Fix:
No patched version reported
Disclosed:
Oct 10, 2016

Simple Ads Manager [simple-ads-manager] < 2.9.5.118 (closed)

unknown

This plugin is prone to an SQL injection vulnerability, because $whereClause and $whereClauseT and $whereClauseW and $whereClause2W are not escaped. Upgrade the plugin.

Affected:
up to 2.9.5.118
Fixed in:
2.9.5.118
Disclosed:
Jan 30, 2016

Simple Ads Manager <= 2.9.4.116 - SQL Injection

critical

The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ parameter in versions up to, and including, 2.9.4.116 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attacke...

CVSS:
9.8
Affected:
up to 2.9.5.118
Fixed in:
2.9.5.118
Disclosed:
Dec 30, 2015

Simple Ads Manager [simple-ads-manager] < 2.9.5.118

unknown

The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ parameter in versions up to, and including, 2.9.4.116 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attacke...

Affected:
up to 2.9.5.118
Fixed in:
2.9.5.118
Disclosed:
Dec 30, 2015

Simple Ads Manager < 2.9.4.116 - Denial of Service

high

The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file system operations which can result in a denial of service. This makes it possible for unauthenticated attackers to affected...

CVSS:
7.5
Affected:
up to 2.9.4.116
Fixed in:
2.9.4.116
Disclosed:
Jul 2, 2015

Simple Ads Manager [simple-ads-manager] < 2.9.4.116

unknown

The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file system operations which can result in a denial of service. This makes it possible for unauthenticated attackers to affected...

Affected:
up to 2.9.4.116
Fixed in:
2.9.4.116
Disclosed:
Jul 2, 2015

Simple Ads Manager [simple-ads-manager] < 2.5.96 (closed)

unknown

[en] Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path par...

Affected:
up to 2.5.96
Fixed in:
2.5.96
Disclosed:
Apr 21, 2015

CVE-2015-2825 on NVD →

Simple Ads Manager [simple-ads-manager] < 2.7.97 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm par...

Affected:
up to 2.7.97
Fixed in:
2.7.97
Disclosed:
Apr 6, 2015

CVE-2015-2824 on NVD →

Simple Ads Manager < 2.7.97 - Multiple SQL Injections

critical

Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm paramete...

CVSS:
10
Affected:
up to 2.7.97
Fixed in:
2.7.97
Disclosed:
Apr 2, 2015

CVE-2015-2824 on NVD →

Simple Ads Manager 2.5.94 & 2.5.96 - Information Disclosure

medium

WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.

CVSS:
5.3
Affected:
2.5.94 – 2.5.94, 2.5.96 – 2.5.96
Fixed in:
2.5.97
Disclosed:
Apr 2, 2015

CVE-2015-2826 on NVD →

Simple Ads Manager <= 2.5.94 - Arbitrary File Upload

critical

Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path paramete...

CVSS:
9.8
Affected:
up to 2.5.94
Fixed in:
2.5.96
Disclosed:
Apr 1, 2015

CVE-2015-2825 on NVD →

Simple Ads Manager [simple-ads-manager] <= 2.10.0.130 (unfixed + closed)

unknown

The simple-ads-manager WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability. The exploitation of this bug could, among other things, lead to SQL Injection attacks.

Affected:
up to 2.10.0.130
Fix:
No patched version reported

Simple Ads Manager [simple-ads-manager] < 2.9.5.118 (closed)

unknown

The simple-ads-manager WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 2.9.5.118
Fixed in:
2.9.5.118

Simple Ads Manager [simple-ads-manager] < 2.9.4.116 (closed)

unknown

An input validation flow allows an attacker to perform simple file system operations which can result in a denial of service of the current Instance. No authentication is required.

Affected:
up to 2.9.4.116
Fixed in:
2.9.4.116

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database