Junglewise Threat Intelligence

CVE-2025-68872: Eli's WordCents adSense Widget with Analytics Reflected XSS

CVE-2025-68872 · Severity: high · CVSS 7.1 · Published 2026-06-15

Executive brief

A vulnerability exists in a WordPress plugin used for managing Google AdSense advertisements and analytics. An attacker could trick a site administrator or visitor into clicking a malicious link, allowing the attacker to run unauthorized scripts in their browser. This could lead to the theft of login sessions, unauthorized website changes, or the redirection of visitors to malicious websites.

Technical details

The Eli's WordCents adSense Widget with Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). This vulnerability allows an unauthenticated remote attacker to inject malicious scripts into the browser of a victim. Exploitation requires the victim to interact with a specially crafted link or page (User Interaction Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the user, or the injection of malicious HTML payloads. As of the advisory date, no official patch is available.

Affected products

  • Eli's WordCents Eli's WordCents adSense Widget with Analytics <= 1.3.03.27

Timeline

  • 2025-10-23: other: Vulnerability reported by researcher Skalucy
  • 2026-01-16: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD

References