Executive brief
The CM Ad Changer plugin for WordPress, which manages and optimizes website advertising banners, is vulnerable to an attack that could lead to the deletion of advertising content. By tricking a site administrator into clicking a malicious link, an attacker can force the website to permanently delete advertising campaigns, banner records, and uploaded files. This could disrupt site revenue and require manual restoration of marketing assets.
Technical details
The CM Ad Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'cmac_campaigns_action' function. This vulnerability affects all versions up to and including 2.0.7. An unauthenticated attacker can exploit this by inducing a logged-in administrator to perform an action, such as clicking a link, which triggers a forged request. Successful exploitation allows the attacker to permanently delete arbitrary advertising campaigns, including associated banner records and uploaded files. A patch appears to be available in newer versions as indicated by the changeset references.
Affected products
- CreativeMinds CM Ad Changer up to, and including, 2.0.7
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
References
- https://plugins.trac.wordpress.org/browser/cm-ad-changer/tags/2.0.7/backend/cm-ad-changer-backend.php
- https://plugins.trac.wordpress.org/browser/cm-ad-changer/tags/2.0.7/backend/cm-ad-changer-backend.php
- https://plugins.trac.wordpress.org/browser/cm-ad-changer/tags/2.0.7/shared/classes/cmac-data.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3544026%40cm-ad-changer&new=3544026%40cm-ad-changer&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a335c917-3fff-4079-bb38-64cd665c5c38?source=cve