Junglewise Threat Intelligence

CVE-2026-65445: iSaumya Ad Invalid Click Protector broken access control

CVE-2026-65445 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

Ad Invalid Click Protector (AICP) is a WordPress plugin designed to prevent click fraud on advertisements. A security flaw in versions 1.3.0 and earlier allows unauthorized individuals to bypass access controls. This could allow an attacker to interfere with the plugin's protective functions or modify settings without permission, potentially disrupting ad revenue or site operations.

Technical details

A Broken Access Control vulnerability exists in the Ad Invalid Click Protector (AICP) plugin for WordPress (versions <= 1.3.0) due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or modify settings that should be restricted to administrative users. The vulnerability is rated with a CVSS 3.1 score of 6.5, indicating impact on integrity and availability. The issue is resolved in version 1.3.1.

Affected products

  • iSaumya Ad Invalid Click Protector (AICP) <= 1.3.0

Timeline

  • 2026-07-08: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-27: advisory: CVE published and NVD record created
  • 2026-07-27: patched: Version 1.3.1 released to address the vulnerability

References