WPAD is an easy way to grab proxy information and get browsers online, but when it comes to security, this protocol doesn’t make the grade. The current problem with WPAD stems from proxy configurations called PAC files, or proxy auto-configs, which are used to automatically set up browser access to the web while still allowing companies to monitor and manage internet access. If compromised, businesses may inadvertently leak entire URL paths, even for HTTPS websites. Researchers are calling for a protocol redesign to limit attack surface and expose less information.”]
Source: https://securityintelligence.com/news/wpad-leaks-could-mean-flood-of-url-trouble/

