Description
Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5.
Published: 2025-02-24
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Missing Authorization flaw in the revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue plugin, affecting all releases from the earliest version up to and including 1.5. It allows an attacker who can access the WordPress site (even with limited privileges such as a basic editor role) to alter ad‑insertion settings without proper authorization. Such changes could modify how ads are displayed, potentially diverting revenue streams or serving improper advertising content. The weakness is identified as CWE‑862.

Affected Systems

WordPress sites that use the revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue plugin on versions 1.5 or earlier. The plugin is distributed by revenueflex and commonly installed via the WordPress plugin repository. No specific operating system or web server version is required for exploitation; the issue resides entirely within the plugin's PHP code.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity due to the potential for significant impact on the site's monetization and user experience. The EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is relatively low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the WordPress administrative interface, where any user who has access to the plugin settings page, even without explicit editorial permissions, can modify ad configuration if the plugin code does not properly validate access control. This could allow attackers to redirect revenue streams or inject malicious advertising content.

Generated by OpenCVE AI on May 1, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Auto Ad Inserter plugin to a version newer than 1.5, ensuring that the latest security fixes are applied.
  • Review and tighten WordPress role permissions so that only administrators or explicitly authorized users can access the plugin configuration page.
  • If an immediate update cannot be performed, implement a temporary workaround by restricting access to the plugin settings using a role‑based access control plugin or by modifying the site's .htaccess or web server configuration to limit URL access to trusted IP addresses.

Generated by OpenCVE AI on May 1, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4332 Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through 1.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through 1.5. Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5.
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 24 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through 1.5.
Title WordPress Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue Plugin <= 1.5 - Settings Change vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:47.337Z

Reserved: 2025-02-21T16:45:27.525Z

Link: CVE-2025-27296

cve-icon Vulnrichment

Updated: 2025-02-24T16:16:37.360Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:15.423

Modified: 2026-06-17T09:03:21.320

Link: CVE-2025-27296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:00:16Z

Weaknesses