Impact
The vulnerability is a missing authorization flaw that allows users to exploit incorrectly configured access control security levels within the Universal Google Adsense and Ads manager plugin. This flaw means that attackers can perform actions that should be restricted to privileged users, such as adding, editing, or deleting advertisement configurations and other administrative functions. The impact is the unauthorized alteration of advertising settings, which can lead to defacement, monetization theft, or other changes within the site without proper authentication or authorization.
Affected Systems
The issue affects the WordPress plugin Universal Google Adsense and Ads manager by themebeez, specifically all versions from the earliest release through version 1.1.8. No other versions or products were identified as affected.
Risk and Exploitability
With a CVSS score of 5.3 the flaw represents moderate severity, while an EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an unauthenticated or low‑privileged user interacting with the plugin’s administrative endpoints, taking advantage of the missing permission checks to execute privileged operations.
OpenCVE Enrichment