Description
Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads: from n/a through <= 2.0.87.1.
Published: 2025-03-31
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ads by WPQuads (Quick Adsense Reloaded) plugin contains a missing authorization check that permits users to invoke plugin functions beyond their role. This flaw, classified as CWE‑862, lets an attacker alter ad configurations, view ad statistics, or perform other privileged actions that should be restricted to administrators or editors. The potential impact is the compromise of the WordPress site’s editorial workflow and the unauthorized manipulation of advertising settings, which can lead to revenue loss and reputational damage.

Affected Systems

All WordPress installations that have the Ads by WPQuads plugin version 2.0.87.1 or earlier installed are vulnerable. The issue spans every release from the initial build up to and including 2.0.87.1; no other WordPress core or plugins are specifically affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently uncommon and not widespread. The vulnerability is not listed in the CISA KEV catalog, implying it has not yet been widely exploited. Based on the description, the likely attack vector is via the plugin’s exposed HTTP endpoints, which can be accessed by any authenticated user lacking proper privileges; in the worst case the endpoint may be publicly reachable. No complex prerequisites are noted, so the attack may be accessible to a broad range of threat actors.

Generated by OpenCVE AI on May 2, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ads by WPQuads plugin to a version that includes the broken access control fix.
  • If an immediate update is not feasible, restrict access to the plugin’s admin URLs by configuring WordPress role permissions or applying a web‑application firewall rule.
  • Disable or uninstall the Ads by WPQuads plugin until a patched version is available.
  • Configure WordPress so that only administrators or editors can invoke the plugin’s privileged functions.

Generated by OpenCVE AI on May 2, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8710 Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ads by WPQuads: from n/a through 2.0.87.1. Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads: from n/a through <= 2.0.87.1.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Mon, 31 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Title WordPress Ads by WPQuads plugin <= 2.0.87.1 - Broken Access Control Vulnerability

Mon, 31 Mar 2025 06:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.989Z

Reserved: 2025-03-26T09:21:01.288Z

Link: CVE-2025-30855

cve-icon Vulnrichment

Updated: 2025-03-31T15:52:37.768Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T06:15:30.310

Modified: 2026-04-23T15:27:12.007

Link: CVE-2025-30855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:00:13Z

Weaknesses