Executive brief
Ad Invalid Click Protector (AICP) is a WordPress plugin designed to prevent click fraud on advertisements. A security flaw in versions 1.3.0 and earlier allows unauthorized individuals to bypass access controls. This could allow an attacker to interfere with the plugin's protective functions or modify settings without permission, potentially disrupting ad revenue or site operations.
Technical details
A Broken Access Control vulnerability exists in the Ad Invalid Click Protector (AICP) plugin for WordPress (versions <= 1.3.0) due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or modify settings that should be restricted to administrative users. The vulnerability is rated with a CVSS 3.1 score of 6.5, indicating impact on integrity and availability. The issue is resolved in version 1.3.1.
Affected products
- iSaumya Ad Invalid Click Protector (AICP) <= 1.3.0
Timeline
- 2026-07-08: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-27: advisory: CVE published and NVD record created
- 2026-07-27: patched: Version 1.3.1 released to address the vulnerability