Simple Ads Manager [simple-ads-manager] >= 2.5.94 - <= 2.5.96
unknown
[en] WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
- Affected:
- 2.5.94 – 2.5.96
- Fixed in:
- 2.5.96
- Disclosed:
- Sep 20, 2017
CVE-2015-2826 on NVD →
Simple Ads Manager <= 2.9.8.125 - Unauthenticated PHP Objection Injection
high
The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.8.125 via deserialization of untrusted input in the vulnerable function 'unserialize'. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. I...
- CVSS:
- 8.3
- Affected:
- up to 2.10.0.130
- Fixed in:
- 2.10.0.130
- Disclosed:
- Mar 17, 2017
Simple Ads Manager [simple-ads-manager] < 2.10.0.130
unknown
The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.8.125 via deserialization of untrusted input in the vulnerable function 'unserialize'. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. I...
- Affected:
- up to 2.10.0.130
- Fixed in:
- 2.10.0.130
- Disclosed:
- Mar 17, 2017
SAM Pro (Free Edition) < 1.9.7.69 & Simple Ads Manager <= 2.10.0.130 & SAM Pro Lite < 1.9.0.53 - Local/Remote File Inclusion
high
The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7.68 via the 'wap' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to b...
- CVSS:
- 8.8
- Affected:
- up to 2.10.0.130
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2016
Simple Ads Manager [simple-ads-manager] <= 2.10.0.130 (unfixed)
unknown
The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7.68 via the 'wap' parameter. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to b...
- Affected:
- up to 2.10.0.130
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2016
Simple Ads Manager [simple-ads-manager] < 2.9.5.118 (closed)
unknown
This plugin is prone to an SQL injection vulnerability, because $whereClause and $whereClauseT and $whereClauseW and $whereClause2W are not escaped.
Upgrade the plugin.
- Affected:
- up to 2.9.5.118
- Fixed in:
- 2.9.5.118
- Disclosed:
- Jan 30, 2016
Simple Ads Manager <= 2.9.4.116 - SQL Injection
critical
The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ parameter in versions up to, and including, 2.9.4.116 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attacke...
- CVSS:
- 9.8
- Affected:
- up to 2.9.5.118
- Fixed in:
- 2.9.5.118
- Disclosed:
- Dec 30, 2015
Simple Ads Manager [simple-ads-manager] < 2.9.5.118
unknown
The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ parameter in versions up to, and including, 2.9.4.116 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attacke...
- Affected:
- up to 2.9.5.118
- Fixed in:
- 2.9.5.118
- Disclosed:
- Dec 30, 2015
Simple Ads Manager < 2.9.4.116 - Denial of Service
high
The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file
system operations which can result in a denial of service. This makes it possible for unauthenticated attackers to affected...
- CVSS:
- 7.5
- Affected:
- up to 2.9.4.116
- Fixed in:
- 2.9.4.116
- Disclosed:
- Jul 2, 2015
Simple Ads Manager [simple-ads-manager] < 2.9.4.116
unknown
The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file
system operations which can result in a denial of service. This makes it possible for unauthenticated attackers to affected...
- Affected:
- up to 2.9.4.116
- Fixed in:
- 2.9.4.116
- Disclosed:
- Jul 2, 2015
Simple Ads Manager [simple-ads-manager] < 2.5.96 (closed)
unknown
[en] Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path par...
- Affected:
- up to 2.5.96
- Fixed in:
- 2.5.96
- Disclosed:
- Apr 21, 2015
CVE-2015-2825 on NVD →
Simple Ads Manager [simple-ads-manager] < 2.7.97 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm par...
- Affected:
- up to 2.7.97
- Fixed in:
- 2.7.97
- Disclosed:
- Apr 6, 2015
CVE-2015-2824 on NVD →
Simple Ads Manager < 2.7.97 - Multiple SQL Injections
critical
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm paramete...
- CVSS:
- 10
- Affected:
- up to 2.7.97
- Fixed in:
- 2.7.97
- Disclosed:
- Apr 2, 2015
CVE-2015-2824 on NVD →
Simple Ads Manager 2.5.94 & 2.5.96 - Information Disclosure
medium
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
- CVSS:
- 5.3
- Affected:
- 2.5.94 – 2.5.94, 2.5.96 – 2.5.96
- Fixed in:
- 2.5.97
- Disclosed:
- Apr 2, 2015
CVE-2015-2826 on NVD →
Simple Ads Manager <= 2.5.94 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path paramete...
- CVSS:
- 9.8
- Affected:
- up to 2.5.94
- Fixed in:
- 2.5.96
- Disclosed:
- Apr 1, 2015
CVE-2015-2825 on NVD →
Simple Ads Manager [simple-ads-manager] <= 2.10.0.130 (unfixed + closed)
unknown
The simple-ads-manager WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability. The exploitation of this bug could, among other things, lead to SQL Injection attacks.
- Affected:
- up to 2.10.0.130
- Fix:
- No patched version reported
Simple Ads Manager [simple-ads-manager] < 2.9.5.118 (closed)
unknown
The simple-ads-manager WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 2.9.5.118
- Fixed in:
- 2.9.5.118
Simple Ads Manager [simple-ads-manager] < 2.9.4.116 (closed)
unknown
An input validation flow allows an attacker to perform simple file system operations which can result in a denial of service of the current Instance. No authentication is required.
- Affected:
- up to 2.9.4.116
- Fixed in:
- 2.9.4.116
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database