← WordPress Vulnerabilities
WordPress security by component

Ad Invalid Click Protector (AICP)

Ad Invalid Click Protector (AICP) is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: ad-invalid-click-protector

CVE-2026-65445: Ad Invalid Click Protector exposes an unauthenticated privileged operation

Ad Invalid Click Protector through 1.3.0 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version1.3.1
Safe version
Jul 27, 2026 CVE-2026-65445
Ad Invalid Click Protector exposes an unauthenticated privileged operation
Ad Invalid Click Protector through 1.3.0 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
1.3.1
CVE6.5
NVDPending
May 02, 2022 CVE-2022-0191
Ad Invalid Click Protector (AICP): Cross-site request forgery
Ad Invalid Click Protector (AICP) is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Feb 14, 2022 CVE-2022-0190
Ad Invalid Click Protector (AICP): SQL injection
Ad Invalid Click Protector (AICP) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8