Retour à la veille

CVE-2026-89050

Publié : 13 septembre 2026
Modifié : 13 septembre 2026
Lien officiel NVD
Score CVSS
4.3
MEDIUM

Description détaillée

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Références et Patchs