WordPress Woody Ad Snippets prior to 2.2.5 is susceptible to cross-site scripting and remote code execution via admin/includes/class.import.snippet.php, which allows unauthenticated options import as demonstrated by storing a cross-site scripting payload for remote code execution.
View the template here CVE-2019-15858.yaml
References:
https://wpvulndb.com/vulnerabilities/9490