Impact
The Advanced Ads – Ad Manager & AdSense plugin contains a flaw that allows unauthenticated attackers to invoke arbitrary PHP functions whose names begin with "get_the_" through the select_one() AJAX handler. This results in limited code execution or information disclosure by exploiting the plugin’s dynamic function call mechanism, which is a form of improper code generation. The flaw corresponds to CWE-94, Improper Control of Generation of Code.
Affected Systems
The vulnerability affects the Advanced Ads plugin for WordPress versions up to and including 2.0.12, used by websites that rely on monetizemore’s Ad Manager & AdSense tooling.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity impact, while the EPSS score of less than 1% suggests a low current exploitation likelihood. The exploit requires no special privileges; an attacker can directly target the AJAX endpoint from any unprivileged network location. Since the plugin is widely used, administrators should treat the issue as critical even though it is not listed in the CISA KEV catalog.
OpenCVE Enrichment