CVE-2026-89050

Summary

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

Affected Software

VendorProductVersion RangeStatus
UnknownQuads Ads Manager for Google AdSense3.0.4 < 3.0.5affected

Weaknesses

  • CWE-345 Insufficient Verification of Data Authenticity

References