
PEACH
Un framework di isolamento del tenant
CVE-2026-89050 is a payment verification bypass vulnerability in the Quads Ads Manager for Google AdSense WordPress plugin affecting versions before 3.0.5. The flaw allows authenticated users (Subscriber-level and above) to obtain paid ad placements without completing payment by exploiting an unverified success return URL. It was publicly disclosed on September 11, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (WPScan, GitHub Advisory).
The vulnerability is classified as CWE-345 (Insufficient Verification of Data Authenticity). The plugin marks an ad-selling order as paid upon receiving a success return URL callback without actually verifying with the configured payment gateway that the transaction was completed. An attacker with at least Subscriber-level access can manipulate or directly trigger the success return URL to bypass payment, causing the system to register a fraudulent paid order. No complex exploitation technique is required — the attack vector is network-based with low attack complexity and no user interaction needed (WPScan, GitHub Advisory).
Successful exploitation allows authenticated users to fraudulently obtain premium ad placements on WordPress sites without paying, resulting in direct financial loss for site operators. The integrity impact is limited to the ad-ordering workflow — there is no confidentiality breach or availability impact. The vulnerability does not enable lateral movement or system-level compromise, but repeated abuse could result in significant revenue loss for sites monetizing ad space through this plugin (WPScan, GitHub Advisory).
No public proof-of-concept exploit is currently available; WPScan has indicated a PoC will be published on September 25, 2026, to allow time for users to update (WPScan). There is no evidence of active in-the-wild exploitation, and the EPSS score is approximately 0.102%, placing it in the 1st percentile for exploitation likelihood (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported.
quick-adsense-reloaded) in a version prior to 3.0.5, using tools like WPScan or manual inspection of plugin directories.Site administrators should immediately upgrade the Quads Ads Manager for Google AdSense WordPress plugin to version 3.0.5 or later, which introduces proper payment gateway verification before marking orders as paid (WPScan, GitHub Advisory). No official workaround short of upgrading has been published. As a remediation step, administrators should audit all recent ad orders marked as paid to identify any fraudulent transactions that may have bypassed payment verification prior to patching.
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of September 7–13, 2026, noting it as part of a broader set of plugin vulnerabilities disclosed that week. The vulnerability was discovered and submitted by researcher JunHee CHO (WPScan). No significant broader media coverage or notable community debate has been observed given the moderate severity and limited exploitation potential.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."