Description
Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data.

This issue affects Advanced Ads: from n/a through 2.0.26.
Published: 2026-10-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an Authorization Bypass Through User‑Controlled Key flaw in the Monetizemore Advanced Ads WordPress plugin. A malicious actor can supply a crafted key value to the plugin’s data‑retrieval endpoints and extract embedded sensitive information such as ad configuration secrets, tracking identifiers, or internal analytics data. This flaw exposes confidential data without requiring privileged access, undermining the confidentiality of the site’s advertising infrastructure.

Affected Systems

WordPress sites that use the Monetizemore Advanced Ads plugin, specifically any installation running a version ranging from the earliest release through 2.0.26. All releases prior to or equal to 2.0.26 are considered vulnerable, as the issue persists across the entire set of affected versions.

Risk and Exploitability

While the CVSS score of 4.3 indicates a moderate severity, the EPSS value is not available, and there is no current listing in the CISA KEV catalog. The likely attack vector is remote, via crafted HTTP requests to the plugin’s endpoints, and requires knowledge of the vulnerable user‑controlled key. Although exploitation does not demand elevated privileges, the attacker can obtain sensitive configuration data that could facilitate further attacks or disclosures.

Generated by OpenCVE AI on October 2, 2026 at 10:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Advanced Ads plugin to the latest version that contains the fix; consult the official plugin repository or the publisher’s advisory for the specific release.
  • If an immediate update cannot be performed, deactivate or uninstall the Advanced Ads plugin to eliminate the vulnerable code base.
  • As a temporary containment measure, restrict access to the plugin’s endpoints by enabling a web application firewall or configuring .htaccess rules to allow only authenticated users or a pre‑approved list of IP addresses.

Generated by OpenCVE AI on October 2, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26.
Title WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-02T17:52:42.348Z

Reserved: 2026-09-21T00:20:20.798Z

Link: CVE-2026-94180

cve-icon Vulnrichment

Updated: 2026-10-02T17:52:29.895Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:09.010

Modified: 2026-10-02T18:17:07.760

Link: CVE-2026-94180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T11:00:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key