Description
Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6.
Published: 2025-05-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the Martins Free Monetized Ad Exchange Network WordPress plugin that enables an attacker to inject reflected cross‑site scripting code. When an authenticated user or passive visitor follows a specially crafted request, the plugin reflects unsanitized input back to the browser, allowing execution of arbitrary JavaScript in the victim’s context, which can lead to defacement, credential theft, or further infection. The weakness is identified as CWE‑352.

Affected Systems

The affected product is the Martins Free Monetized Ad Exchange Network plugin distributed by bundgaard, version 1.0.6 and any earlier releases. WordPress sites that have this plugin installed and have not upgraded beyond 1.0.6 are vulnerable.

Risk and Exploitability

The CVSS base score of 7.1 denotes a high impact, while the EPSS score of less than 1% indicates a very low probability of exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely perpetrate the CSRF by embedding the malicious link in a website or email that a privileged user might unknowingly visit, or by leveraging another site that hosts the plugin. Successful exploitation would result in client‑side script execution, potentially compromising user sessions or defacing the site. Current mitigation is to apply the vendor patch or otherwise block the vulnerable endpoint.

Generated by OpenCVE AI on April 30, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to the latest available version (greater than 1.0.6).
  • If an update is unavailable, disable or remove the Martins Free Monetized Ad Exchange Network plugin entirely.
  • If disabling the plugin is not feasible, ensure that strict CSRF token verification is enabled or configure a web application firewall to filter and block suspicious requests to the vulnerable endpoints.

Generated by OpenCVE AI on April 30, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13763 Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.11. Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6.
Title WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.11 - Cross Site Request Forgery (CSRF) vulnerability WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6. Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.11.
Title WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.11 - Cross Site Request Forgery (CSRF) vulnerability
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5. Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6.
Title WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.5 - CSRF to XSS vulnerability WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.00019}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.
Title WordPress Martins Free Monetized Ad Exchange Network plugin <= 1.0.5 - CSRF to XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:14:52.263Z

Reserved: 2025-05-07T10:44:40.883Z

Link: CVE-2025-47620

cve-icon Vulnrichment

Updated: 2025-05-07T17:19:25.455Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:15.040

Modified: 2026-04-28T19:32:29.013

Link: CVE-2025-47620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:30:26Z

Weaknesses