CVE-2026-89050
Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
| Vendor | unknown |
| Product | quads ads manager for google adsense |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown quads ads manager for google adsense
Be the first to know when new medium vulnerabilities affecting unknown quads ads manager for google adsense are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Quads Ads Manager for Google AdSense
3.0.4 < 3.0.5
References
Credits
JunHee CHO WPScan