Junglewise Threat Intelligence

CVE-2026-42732: WPQuads Ads by WPQuads broken authentication via input manipulation

CVE-2026-42732 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: WPQuads Ads by WPQuads. Vendors: WPQuads.

Executive brief

Ads by WPQuads is a popular WordPress plugin used to manage and display advertisements on websites. A security flaw in the plugin allows unauthorized individuals to manipulate input data, potentially bypassing authentication checks. This could allow an attacker to perform administrative actions or gain unauthorized access to the website's management features.

Technical details

The Ads by WPQuads (quick-adsense-reloaded) plugin for WordPress (versions up to and including 3.0.2) suffers from a broken authentication vulnerability categorized under CWE-1284 (Improper Validation of Specified Quantity in Input). The flaw allows an unauthenticated remote attacker to manipulate input data to bypass security checks. This can be leveraged to execute actions that are typically restricted to high-privileged users, potentially leading to full administrative access. The vulnerability is addressed in version 3.0.3.

Affected products

  • WPQuads Ads by WPQuads (quick-adsense-reloaded) <= 3.0.2

Timeline

  • 2026-04-24: other: Reported by Bas Albers
  • 2026-05-24: advisory: Patchstack advisory published
  • 2026-05-27: disclosed: CVE published to NVD
  • 2026-05-27: patched: Fixed in version 3.0.3

References

Related threats