Impact
The affected WordPress plugin fails to confirm that a an ad-selling order as paid. Because the payment completion is not verified, anyone who can submit an order can trick the system into treating the order as fully paid, allowing unauthorized a payment bypass that undermines the plugin’s revenue model.
Affected Systems
The vulnerability applies to all releases of Quads Ads Manager for Google AdSense older than version 3.0.5. Site administrators running those older versions are exposed if their configuration permits users to place ad-selling orders. The issue is limited to the plugin code and not to core WordPress or other themes.
Risk and Exploitability
With a CVSS score of 4.3 the flaw is ofSS score of < 1% indicates the flaw is not listed in CISA's KEV catalog. Attackers would need only the ability to initiate an ad-selling order; additional privileges are not required. The likely attack vector is inferred from the description that the plugin does not check payment completion, suggesting manipulation of the payment gateway’s return URL or faking a success response.
OpenCVE Enrichment