ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-4380
Unauthenticated Local File Inclusion in WordPress Ads Pro Plugin (≤ 4.89)

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager, a WordPress plugin by scripteo, is vulnerable to an unauthenticated local file inclusion (CWE-98) affecting all versions up to and including 4.89. The flaw resides in the bsa_template parameter of the bsa_preview_callback function, which fails to properly restrict which files can be included, so a remote, unauthenticated attacker can supply a crafted path that causes the server to include and execute arbitrary local files. Any PHP code inside an included file runs in the web server's context, enabling attackers to bypass access controls, obtain sensitive data, and achieve code execution where attacker-controllable .php files can be uploaded or already exist on the site. Any WordPress site running the plugin at version 4.89 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 40.4% EPSS score (99th percentile) indicates a high likelihood of exploitation within the next 30 days.

Do: Update the plugin to a patched release newer than version 4.89 as soon as one is available, or deactivate the plugin until the patch is applied. Since the flaw allows arbitrary file inclusion and potential code execution, check the site for unexpected .php uploads, modified files, and rogue administrator accounts, and review access logs for unauthenticated requests containing bsa_template parameters.

9.8
group max
40%
  • scripteo Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager (WordPress plugin) All versions up to and including 4.89 (no fixed version specified in the source data)
moderateroughly 20,000+ sites (plugin is listed with approximately 20k active installs on the WordPress.org directory)
CVE-2024-13322
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD description · AI analysis pending
7.52%
  • scripteo ads pro
CVE-2024-52428
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-bo

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro allows PHP Local File Inclusion.This issue affects Ads Booster by Ads Pro: from n/a through <= 1.12.

NVD description · AI analysis pending
9.8<1%
  • scripteo ads booster by ads pro