Ads Pro <= 5.0 - Missing Authorization
medium
The Ads Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0
- Fixed in:
- 5.1
- Disclosed:
- Feb 20, 2026
CVE-2026-25388 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 5.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in scripteo Ads Pro ap-plugin-scripteo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads Pro: from n/a through <= 5.0.
- Affected:
- up to 5.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25388 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ parameter in all versions up to, and including, 4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- CVSS:
- 7.5
- Affected:
- up to 4.95
- Fix:
- No patched version reported
- Disclosed:
- Nov 23, 2025
CVE-2025-7402 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Time-Based SQL Injection via ‘bsa_pro_id'
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...
- CVSS:
- 7.5
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-5339 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection via oid
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘oid’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...
- CVSS:
- 7.5
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-6437 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery to PHP Code Injection in bsaCreateAdTemplate
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.89. This is due to missing or incorrect nonce validation on the bsaCreateAdTemplate function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 8.8
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-6459 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...
- CVSS:
- 7.5
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-4381 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion to Remote Code Execution
critical
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up to, and including, 4.89. This is due to the presence of a SQL Injection vulnerability and Local File Inclusion vulnerability that can be cha...
- CVSS:
- 9.8
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-4689 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbi...
- CVSS:
- 8.1
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-4380 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.88 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scripteo Ads Pro Plugin allows PHP Local File Inclusion. This issue affects Ads Pro Plugin: from n/a through 4.88.
- Affected:
- up to 4.88
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-46444 on NVD →
Ads Pro Plugin <= 4.89 - Unauthenticated Local File Inclusion
critical
The Ads Pro Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.89. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contro...
- CVSS:
- 9.8
- Affected:
- up to 4.89
- Fix:
- No patched version reported
- Disclosed:
- May 21, 2025
CVE-2025-46444 on NVD →
Ads Pro Plugin <= 5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ads Pro Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 5.0
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-46464 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.88 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scripteo Ads Pro Plugin allows Stored XSS. This issue affects Ads Pro Plugin: from n/a through 4.88.
- Affected:
- up to 4.88
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-46464 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] < 4.89
unknown
[en] The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...
- Affected:
- up to 4.89
- Fixed in:
- 4.89
- Disclosed:
- May 2, 2025
CVE-2024-13322 on NVD →
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.88 - Unauthenticated SQL Injection
high
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...
- CVSS:
- 7.5
- Affected:
- up to 4.88
- Fixed in:
- 4.89
- Disclosed:
- May 1, 2025
CVE-2024-13322 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-4380 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-4689 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-4381 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-6459 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-6437 on NVD →
Ads Pro Plugin [ap-plugin-scripteo] <= 4.89 (unfixed)
unknown
- Affected:
- up to 4.89
- Fix:
- No patched version reported
CVE-2025-5339 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database