Executive brief
Ads by WPQuads is a popular WordPress plugin used to manage and display advertisements on websites. A security flaw in versions 3.0.3 and earlier allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. This could allow an attacker to modify advertisement settings or configurations, potentially disrupting site revenue or altering site content.
Technical details
The Ads by WPQuads plugin for WordPress (versions <= 3.0.3) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An attacker authenticated with a low-level 'Subscriber' role can exploit this flaw to execute functions or modify settings that should be restricted to higher-privileged users like Administrators. The vulnerability is network-reachable and does not require user interaction, though it does require a valid login. The issue is addressed in version 3.0.4.
Affected products
- Ads WPQuads Ads by WPQuads <= 3.0.3
Timeline
- 2026-06-09: other: Reported by researcher
- 2026-06-29: disclosed: Public disclosure and NVD publication
- 2026-06-29: patched: Patch released in version 3.0.4