Impact
The Advanced Ads plugin for WordPress is vulnerable to remote code execution in versions up to and including 2.0.14 via the 'change-ad__content' shortcode parameter. An attacker who can authenticate with editor-level permissions supplies malicious code in the shortcode, which the plugin executes on the server. This flaw, classified as CWE-94, lets the attacker run arbitrary PHP on the site, compromising the confidentiality, integrity, and availability of the site and potentially the underlying server.
Affected Systems
The affected product is the Advanced Ads – Ad Manager & AdSense plugin, produced by monetizemore, version 2.0.14 and earlier. Any WordPress site that has this plugin installed and a user with editor or higher privileges is vulnerable. The version range specified is up to 2.0.14; newer releases presumably contain the fix.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity vulnerability. The EPSS value of less than 1% suggests a low likelihood of active exploitation at this time, and the vulnerability is not currently listed in CISA’s KEV catalog. However, because the flaw requires authenticated access, attackers with editor or higher roles can exploit it; thus an attacker with such permissions could fully compromise the site. Administrators should therefore consider the risk significant and treat this as a high‑priority issue.
OpenCVE Enrichment