Junglewise Threat Intelligence

CVE-2026-39698: PublisherDesk The Publisher Desk ads.txt missing authorization

CVE-2026-39698 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Publisher Desk ads.txt plugin for WordPress, which helps website owners manage their advertising authorization files, contains a security flaw in its access control settings. An unauthorized individual could exploit this to perform actions or modify settings that should be restricted to administrators. This could potentially allow an attacker to interfere with the site's advertising revenue or configuration.

Technical details

A missing authorization vulnerability (CWE-862) exists in the PublisherDesk 'The Publisher Desk ads.txt' plugin for WordPress through version 1.5.0. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before allowing certain actions. An unauthenticated remote attacker can exploit this lack of authorization to execute functions or modify configurations that should be restricted to higher-privileged users. As of the advisory date, no official patch has been released.

Affected products

  • PublisherDesk The Publisher Desk ads.txt <= 1.5.0

Timeline

  • 2026-01-28: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-27: advisory: Initial disclosure by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References