CVE-2025-10487

HIGH

Advanced Ads WordPress Plugin <=2.0.12 - Unauthenticated AJAX Function Exposure

Title source: manual
STIX 2.1

Description

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 via the select_one() function. This is due to the endpoint not properly restricting access to the AJAX endpoint or limiting the functions that can be called to safe functions. This makes it possible for unauthenticated attackers to call arbitrary functions beginning with get_the_ like get_the_excerpt which can make information exposure possible.

Scores

CVSS v3 7.3
EPSS 0.0039
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
monetizemore/Advanced Ads – Ad Manager & AdSense < 2.0.12
Published Nov 01, 2025
Tracked Since Feb 18, 2026