WordPress Plugin Vulnerabilities
Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL
Description
The plugin does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
JunHee CHO
Submitter
JunHee CHO
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 2 days ago)
Last Updated
2026-09-11 (about 2 days ago)