PT-2025-27586 · WordPress · The Ads Pro Plugin

Trương Hữu Phúc

+1

·

Published

2025-07-02

·

Updated

2025-07-09

·

CVE-2025-4380

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager versions up to, and including, 4.89
Description: The issue allows unauthenticated attackers to include and execute arbitrary files on the server via the bsa template parameter of the bsa preview callback function. This enables the execution of any PHP code in those files, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included, or already exist on the site.
Recommendations: For versions up to, and including, 4.89, as a temporary workaround, consider disabling the bsa preview callback function until a patch is available. Restrict access to the bsa template parameter to minimize the risk of exploitation. Avoid using the bsa template parameter in the affected function until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-4380

Affected Products

The Ads Pro Plugin