Executive brief
The Moneytizer plugin for WordPress, which is used by website owners to manage advertising and monetization, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions or access settings that should be restricted to administrators. While the impact is considered moderate, it could allow an attacker to interfere with the plugin's configuration or site monetization settings.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the lvaudore The Moneytizer plugin for WordPress through version 10.0.10. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this by sending crafted network requests to trigger actions that should require higher privileges. This can result in unauthorized modification of plugin settings or data. As of the advisory date, no official patch has been released.
Affected products
- lvaudore The Moneytizer <= 10.0.10
Timeline
- 2026-01-23: other: Reported by Nguyen Ba Khanh
- 2026-02-22: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published to NVD