Junglewise Threat Intelligence

CVE-2026-54816: Monetizemore Advanced Ads code injection in WordPress plugin

CVE-2026-54816 · Severity: high · CVSS 7.5 · Published 2026-06-17

Executive brief

Advanced Ads is a popular WordPress plugin used by website owners to manage and display advertisements. A security vulnerability in this plugin allows an attacker with basic contributor-level access to inject and execute malicious code on the server. This could lead to a complete takeover of the website, theft of sensitive data, or the installation of backdoors for persistent access.

Technical details

A code injection vulnerability (CWE-94) exists in the Monetizemore Advanced Ads plugin for WordPress in versions up to and including 2.0.21. The flaw allows an attacker with 'Contributor' or higher privileges to inject arbitrary code that is subsequently executed by the server. While the attack vector is over the network, it requires a low level of authentication and involves high complexity (AC:H) according to the CVSS metric. Successful exploitation results in full Remote Code Execution (RCE), compromising the confidentiality, integrity, and availability of the affected site. The issue is resolved in version 2.0.22.

Affected products

  • Monetizemore Advanced Ads up to 2.0.21

Timeline

  • 2026-04-10: other: Vulnerability reported by researcher Nguyen Ba Khanh
  • 2026-06-17: advisory: Advisory published by Patchstack and NVD
  • 2026-06-17: patched: Patch released in version 2.0.22

References