Executive brief
Ads by WPQuads is a popular WordPress plugin used to manage and display advertisements on websites. A security flaw in versions 3.0.3 and earlier allows unauthorized individuals to access sensitive system information without logging in. This exposure could provide attackers with the data needed to launch more sophisticated attacks or gain further access to the website's backend.
Technical details
The Ads by WPQuads plugin for WordPress is vulnerable to sensitive data exposure (CWE-497) in versions up to 3.0.3. The vulnerability allows an unauthenticated remote attacker to access sensitive system information that should be restricted. This occurs due to insufficient access controls on certain plugin components or data outputs. An attacker can exploit this by sending a specially crafted network request to the affected site. The exposed information can be leveraged to facilitate further attacks against the host environment. The issue is resolved in version 3.0.4.
Affected products
- Ads WPQuads Ads by WPQuads <= 3.0.3
Timeline
- 2026-04-29: other: Reported by HaiND
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date