CVE-2026-89050

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

  • Published Sep 13, 2026
  • CVSS 4.3 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-89050 at the National Vulnerability Database