Description
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a subscriber‑level broken access control in versions of the WordPress Ads by WPQuads plugin up to 3.0.3. The plugin fails to enforce proper role checks, allowing authenticated subscribers to perform privileged actions that should be restricted to administrators. This permits an attacker who has a subscriber account to manipulate or delete ad settings, potentially affecting site revenue or user experience. The weakness is mapped to CWE‑862, which signifies unauthorized access to privileged functions.

Affected Systems

WordPress sites using the Ads by WPQuads plugin, versions 3.0.3 and earlier. The vendor noted the problem for Ads WPQuads: Ads by WPQuads, and affected all WordPress installations that had this plugin deployed without upgrading beyond 3.0.3.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is not available, so the exploitation probability remains uncertain. The vulnerability is known to be in use on live sites and is not listed in the CISA KEV catalog. Attackers would require a valid subscriber account and access to the plugin’s administrative interface; a likely attack vector is through the plugin’s configuration pages or associated REST endpoints, though this inference is based on the described lack of role checks. Because the privilege escalation is limited to the subscriber role, the impact is confined to unauthorized configuration changes, which can compromise the integrity of the site’s advertising functions.

Generated by OpenCVE AI on June 29, 2026 at 17:06 UTC.

Remediation

Vendor Solution

Update the WordPress Ads by WPQuads Plugin to the latest available version (at least 3.0.4).


OpenCVE Recommended Actions

  • Upgrade the WordPress Ads by WPQuads plugin to version 3.0.4 or later.
  • Restrict the plugin’s configuration access to administrator roles only, ensuring that subscriber privileges cannot invoke admin‑level functions.
  • Review WordPress user role assignments to confirm that subscriber accounts are not granted capabilities that allow ad configuration changes.

Generated by OpenCVE AI on June 29, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ads By Wpquads
Ads By Wpquads ads By Wpquads
Wordpress
Wordpress wordpress
Vendors & Products Ads By Wpquads
Ads By Wpquads ads By Wpquads
Wordpress
Wordpress wordpress

Mon, 29 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
Title WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ads By Wpquads Ads By Wpquads
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T10:23:13.738Z

Reserved: 2026-06-24T12:45:19.178Z

Link: CVE-2026-57335

cve-icon Vulnrichment

Updated: 2026-07-01T10:23:10.593Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T09:45:03Z

Weaknesses