Ad Invalid Click Protector (AICP) <= 1.3.0 - Missing Authorization
medium
The Ad Invalid Click Protector (AICP) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jul 27, 2026
CVE-2026-65445 on NVD →
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
critical
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...
- CVSS:
- 10
- Affected:
- 1.2.9 – 1.2.9
- Fixed in:
- 1.2.11
- Disclosed:
- Jun 24, 2024
CVE-2024-6297 on NVD →
Ad Invalid Click Protector (AICP) <= 1.2.5.2 - Cross-Site Request Forgery to Arbitrary Ban Deletion
medium
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans
- CVSS:
- 4.3
- Affected:
- up to 1.2.5.2
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 13, 2022
CVE-2022-0191 on NVD →
Ad Invalid Click Protector (AICP) <= 1.2.5.2 - Reflected Cross-Site Scripting and Cross-Site Request Forgery
medium
The Ad Invalid Click Protector (AICP) WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the page parameter and Cross-Site Request Forgery that allows attackers to delete banned users.
- CVSS:
- 6.1
- Affected:
- up to 1.2.5.2
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 5, 2022
Ad Invalid Click Protector <= 1.2.5 - SQL Injection
high
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jan 14, 2022
CVE-2022-0190 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database