ZeroHour

CVE-2026-89050

CVSS 3.1
4.3 medium
EPSS
Published
()
Modified
Description

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

Ecosystems
WordPress
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.