Description
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
Published: 2026-09-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Payment Bypass
Action: Patch Update
AI Analysis

Impact

The affected WordPress plugin fails to confirm that a an ad-selling order as paid. Because the payment completion is not verified, anyone who can submit an order can trick the system into treating the order as fully paid, allowing unauthorized a payment bypass that undermines the plugin’s revenue model.

Affected Systems

The vulnerability applies to all releases of Quads Ads Manager for Google AdSense older than version 3.0.5. Site administrators running those older versions are exposed if their configuration permits users to place ad-selling orders. The issue is limited to the plugin code and not to core WordPress or other themes.

Risk and Exploitability

With a CVSS score of 4.3 the flaw is ofSS score of < 1% indicates the flaw is not listed in CISA's KEV catalog. Attackers would need only the ability to initiate an ad-selling order; additional privileges are not required. The likely attack vector is inferred from the description that the plugin does not check payment completion, suggesting manipulation of the payment gateway’s return URL or faking a success response.

Generated by OpenCVE AI on September 21, 2026 at 00:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Quads Ads Manager for Google AdSense to version 3.0.5 or later.
  • Limit the ability to place ad-selling orders to authenticated, trusted users by adjusting role capabilities.
  • If an immediate update is not possible, temporarily disable the ad-selling feature or patch the plugin so that it verifies payment completion before marking an order as paid.

Generated by OpenCVE AI on September 21, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
Title Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-14T12:38:35.849Z

Reserved: 2026-09-10T17:05:28.613Z

Link: CVE-2026-89050

cve-icon Vulnrichment

Updated: 2026-09-14T12:36:45.629Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:02.460

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-89050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity