PT-2025-47880 · WordPress · Ads Pro Plugin

Published

2025-11-24

·

Updated

2025-11-26

·

CVE-2025-7402

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager versions prior to 4.95
Description The Ads Pro Plugin for WordPress is susceptible to time-based SQL Injection through the site id parameter. Insufficient input validation and query preparation allow unauthenticated attackers to inject additional SQL queries into existing database queries, potentially enabling the extraction of sensitive information.
Recommendations Update Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager to a version later than 4.95.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-7402

Affected Products

Ads Pro Plugin