Simple Ads Manager < 2.9.4.116 - Denial of Service

2015-07-02 00:00
Michael Kapfer

Strategic Overview

Status
Patched in 2.9.4.116
Affected PluginSimple Ads Manager
Affected Version< 2.9.4.116
CVSS7.5High
CVEN/A
View all Simple Ads Manager vulnerabilities

Vulnerability Overview

The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due to an input validation flaw that allows an attacker to perform simple file system operations which can result in a denial of service. This makes it possible for unauthenticated attackers to affected website to consume memory and CPU resources, thus denying service to legitimate users.

Technical Analysis

REMEDIATION: Update to version 2.9.4.116, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C