Impact
The Advanced Ads – Tracking plugin for WordPress releases older than version 3.0.7 contains an unauthenticated SQL Injection flaw (CWE-89). An attacker can send specially crafted input through the plugin’s web interface to manipulate the database, potentially reading, modifying or deleting data in the site’s database.
Affected Systems
This flaw affects installations of the Advanced Ads – Tracking plugin from Advanced Ads GmbH on WordPress sites that have not migrated to a post‑3.0.7 version. No sub‑version details are supplied, so any release prior to the 3.0.7 threshold is considered vulnerable.
Risk and Exploitability
The CVSS score of 9.3 categorises the problem as critical, and the lack of an EPSS value or KEV listing does not diminish the threat to exposed sites. Because authentication is not required, the attack can be carried out by any user who can reach the WordPress administrative interface, making exploitation likely if the site is publicly accessible.
OpenCVE Enrichment