
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13592 is a Remote Code Execution (RCE) vulnerability in the Advanced Ads – Ad Manager & AdSense plugin for WordPress, affecting versions up to and including 2.0.14. The flaw exists in the change-ad__content shortcode parameter and allows authenticated attackers with editor-level permissions or above to execute arbitrary code on the server. It was published on December 29, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The root cause lies in insufficient sanitization of the change-ad__content shortcode parameter within the plugin's class-ad-plain.php file (line 36 in version 2.0.14), which allows user-supplied input to be evaluated as executable code on the server. Exploitation requires network access and authenticated editor-level (or higher) WordPress credentials, with no user interaction required. The vulnerable code path and a patch changeset are publicly visible in the WordPress plugin repository (WordPress Trac, WordPress Changeset).
Successful exploitation grants an attacker full remote code execution on the WordPress server, resulting in high impact to confidentiality, integrity, and availability. An attacker with editor privileges could read sensitive server data, modify or delete files, install backdoors, or pivot to other systems on the same network. The scope is limited to the affected system, but a compromised WordPress server can expose database credentials, user data, and hosted content (Wordfence, Sucuri Blog).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.0025 (0.25%), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for editor-level authentication, which limits the attacker pool but does not eliminate risk in environments with multiple editors or compromised accounts. The vulnerability has been detected by Qualys (detection ID 530804) (Qualys, Wordfence).
change-ad__content parameter, exploiting the lack of input sanitization in class-ad-plain.php.change-ad__content with encoded or obfuscated payloads); PHP error logs referencing class-ad-plain.php with unexpected evaluation errors.bash, curl, wget, python) following WordPress page rendering events.Users should update the Advanced Ads plugin to a version beyond 2.0.14, which includes the fix applied in changeset 3427297. The patch addresses the improper handling of the change-ad__content shortcode parameter in class-ad-plain.php. As a temporary workaround, site administrators should restrict editor-level access to trusted users only and consider disabling the Advanced Ads plugin until the update can be applied. Monitoring WordPress user activity for unusual shortcode usage is also recommended (WordPress Changeset, Wordfence).
Wordfence included CVE-2025-13592 in its weekly WordPress vulnerability report for December 15, 2025 – January 4, 2026, highlighting it as a notable RCE finding (Wordfence Weekly Report). Sucuri also referenced the vulnerability in its December 2025 patch roundup, advising WordPress administrators to update affected plugins promptly (Sucuri Blog). The vulnerability was also noted in CISA's weekly vulnerability bulletin for the week of December 29, 2025 (CISA Bulletin). Community discussion has been limited, consistent with the low EPSS score and authentication requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."