Executive brief
Advanced Ads – Tracking is a WordPress plugin used by website owners to monitor and analyze the performance of advertisements. A security flaw in this plugin allows unauthenticated attackers to interact directly with the website's database. This could lead to the theft of sensitive information, such as user data or configuration details, and potentially disrupt site operations.
Technical details
A SQL injection vulnerability exists in the Advanced Ads – Tracking plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers, requiring no specific user interaction or privileges. By sending specially crafted requests, an attacker can execute arbitrary SQL queries against the backend database. This can result in the unauthorized retrieval of sensitive data (Confidentiality: High) and minor service disruption (Availability: Low). The issue is resolved in version 3.0.7.
Affected products
- Advanced Ads GmbH Advanced Ads – Tracking < 3.0.7
Timeline
- 2025-08-05: other: Reported by researcher AirBesta
- 2025-09-04: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date