WordPress Woody Ad Snippets prior to 2.2.5 is susceptible to cross-site scripting and remote code execution via admin/includes/class.import.snippet.php, which allows unauthenticated options import as demonstrated by storing a cross-site scripting payload for remote code execution.
id: CVE-2019-15858
info:
name: WordPress Woody Ad Snippets <2.2.5 - Cross-Site Scripting/Remote C
...