Unauthorized Modification of Data in AdFoxly Plugin
CVE-2024-1715
5.3MEDIUM
What is CVE-2024-1715?
The AdFoxly – Ad Manager, AdSense Ads & Ads.txt plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the adfoxly_ad_status() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to enable and disable ads.
Affected Version(s)
AdFoxly – Ad Manager, AdSense Ads & Ads.txt * <= 1.8.5