Executive brief
Ads by WPQuads is a popular WordPress plugin used to manage and display advertisements on websites. A security vulnerability in versions up to 3.0.2 allows unauthorized individuals to manipulate hidden form fields. This could lead to unauthorized changes in how ads are displayed or bypass certain operational restrictions, potentially impacting site revenue or layout integrity.
Technical details
The Ads by WPQuads plugin (quick-adsense-reloaded) for WordPress suffers from an 'Improper Validation of Specified Quantity in Input' vulnerability (CWE-1284). This flaw allows a remote attacker to manipulate hidden fields within the application's forms. The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to unauthorized modification of data or partial service disruption. The issue affects all versions up to and including 3.0.2.
Affected products
- WPQuads Ads by WPQuads (quick-adsense-reloaded) <= 3.0.2
Timeline
- 2026-05-27: disclosed: Initial publication of CVE-2026-42744