CVE-2025-13592: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13592 is a Remote Code Execution (RCE) vulnerability in the Advanced Ads – Ad Manager & AdSense plugin for WordPress, affecting versions up to and including 2.0.14. The flaw exists in the change-ad__content shortcode parameter and allows authenticated attackers with editor-level permissions or above to execute arbitrary code on the server. It was published on December 29, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The root cause lies in insufficient sanitization of the change-ad__content shortcode parameter within the plugin's class-ad-plain.php file (line 36 in version 2.0.14), which allows user-supplied input to be evaluated as executable code on the server. Exploitation requires network access and authenticated editor-level (or higher) WordPress credentials, with no user interaction required. The vulnerable code path and a patch changeset are publicly visible in the WordPress plugin repository (WordPress Trac, WordPress Changeset).

Impact

Successful exploitation grants an attacker full remote code execution on the WordPress server, resulting in high impact to confidentiality, integrity, and availability. An attacker with editor privileges could read sensitive server data, modify or delete files, install backdoors, or pivot to other systems on the same network. The scope is limited to the affected system, but a compromised WordPress server can expose database credentials, user data, and hosted content (Wordfence, Sucuri Blog).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.0025 (0.25%), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for editor-level authentication, which limits the attacker pool but does not eliminate risk in environments with multiple editors or compromised accounts. The vulnerability has been detected by Qualys (detection ID 530804) (Qualys, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Advanced Ads plugin version ≤ 2.0.14 using tools like WPScan or by checking the plugin version in publicly accessible readme files.
  2. Obtain Editor Credentials: Acquire editor-level (or higher) WordPress credentials via phishing, credential stuffing, or exploitation of another vulnerability.
  3. Authenticate: Log in to the WordPress admin panel or use the WordPress REST API/XML-RPC with the obtained credentials.
  4. Craft Malicious Shortcode: Construct a post or page containing a shortcode that passes a malicious payload via the change-ad__content parameter, exploiting the lack of input sanitization in class-ad-plain.php.
  5. Trigger Execution: Publish or preview the crafted content to cause the server to evaluate and execute the injected code.
  6. Achieve Objective: Use the resulting code execution to establish a web shell, exfiltrate data, or perform further lateral movement on the server (WordPress Trac, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to post/page editing endpoints by editor-level accounts containing unusual shortcode parameters (e.g., change-ad__content with encoded or obfuscated payloads); PHP error logs referencing class-ad-plain.php with unexpected evaluation errors.
  • File System: Newly created or modified PHP files in the WordPress uploads directory or plugin directories; presence of web shells or unfamiliar scripts with recent timestamps.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget, python) following WordPress page rendering events.
  • Network: Unexpected outbound connections from the web server to external IPs, particularly following content publication or preview actions by editor accounts.

Mitigation and workarounds

Users should update the Advanced Ads plugin to a version beyond 2.0.14, which includes the fix applied in changeset 3427297. The patch addresses the improper handling of the change-ad__content shortcode parameter in class-ad-plain.php. As a temporary workaround, site administrators should restrict editor-level access to trusted users only and consider disabling the Advanced Ads plugin until the update can be applied. Monitoring WordPress user activity for unusual shortcode usage is also recommended (WordPress Changeset, Wordfence).

Community reactions

Wordfence included CVE-2025-13592 in its weekly WordPress vulnerability report for December 15, 2025 – January 4, 2026, highlighting it as a notable RCE finding (Wordfence Weekly Report). Sucuri also referenced the vulnerability in its December 2025 patch roundup, advising WordPress administrators to update affected plugins promptly (Sucuri Blog). The vulnerability was also noted in CISA's weekly vulnerability bulletin for the week of December 29, 2025 (CISA Bulletin). Community discussion has been limited, consistent with the low EPSS score and authentication requirement.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management