Impact
The vulnerability is an Authorization Bypass Through User‑Controlled Key flaw in the Monetizemore Advanced Ads WordPress plugin. A malicious actor can supply a crafted key value to the plugin’s data‑retrieval endpoints and extract embedded sensitive information such as ad configuration secrets, tracking identifiers, or internal analytics data. This flaw exposes confidential data without requiring privileged access, undermining the confidentiality of the site’s advertising infrastructure.
Affected Systems
WordPress sites that use the Monetizemore Advanced Ads plugin, specifically any installation running a version ranging from the earliest release through 2.0.26. All releases prior to or equal to 2.0.26 are considered vulnerable, as the issue persists across the entire set of affected versions.
Risk and Exploitability
While the CVSS score of 4.3 indicates a moderate severity, the EPSS value is not available, and there is no current listing in the CISA KEV catalog. The likely attack vector is remote, via crafted HTTP requests to the plugin’s endpoints, and requires knowledge of the vulnerable user‑controlled key. Although exploitation does not demand elevated privileges, the attacker can obtain sensitive configuration data that could facilitate further attacks or disclosures.
OpenCVE Enrichment