plugin

Ad Invalid Click Protector Vulnerabilities

5 known security issues reported for the Ad Invalid Click Protector WordPress plugin. Most recent disclosed Jul 27, 2026.

1 critical 1 high 3 medium

Running Ad Invalid Click Protector on your site? Check whether your installed version is affected.

Scan your site free

Ad Invalid Click Protector (AICP) <= 1.3.0 - Missing Authorization

medium

The Ad Invalid Click Protector (AICP) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Jul 27, 2026

CVE-2026-65445 on NVD →

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

critical

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

CVSS:
10
Affected:
1.2.9 – 1.2.9
Fixed in:
1.2.11
Disclosed:
Jun 24, 2024

CVE-2024-6297 on NVD →

Ad Invalid Click Protector (AICP) <= 1.2.5.2 - Cross-Site Request Forgery to Arbitrary Ban Deletion

medium

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

CVSS:
4.3
Affected:
up to 1.2.5.2
Fixed in:
1.2.7
Disclosed:
Apr 13, 2022

CVE-2022-0191 on NVD →

Ad Invalid Click Protector (AICP) <= 1.2.5.2 - Reflected Cross-Site Scripting and Cross-Site Request Forgery

medium

The Ad Invalid Click Protector (AICP) WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the page parameter and Cross-Site Request Forgery that allows attackers to delete banned users.

CVSS:
6.1
Affected:
up to 1.2.5.2
Fixed in:
1.2.7
Disclosed:
Apr 5, 2022

Ad Invalid Click Protector <= 1.2.5 - SQL Injection

high

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 14, 2022

CVE-2022-0190 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database