← WordPress Vulnerabilities
WordPress security by component

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2025; the highest published CVSS base score is 9.8.

Plugin slug: ads-pro

CVE-2025-6459: Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: Cross-site request forgery

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJul 02, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for ads-pro
Safe version
Jul 02, 2025 CVE-2025-6459
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: Cross-site request forgery
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Jul 02, 2025 CVE-2025-6437
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: SQL injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Jul 02, 2025 CVE-2025-5339
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: SQL injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Jul 02, 2025 CVE-2025-4689
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: SQL injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending
Jul 02, 2025 CVE-2025-4381
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: SQL injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Jul 02, 2025 CVE-2025-4380
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: Filesystem traversal
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVD9.8
May 02, 2025 CVE-2024-13322
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager: SQL injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending