Remote Code Execution Vulnerability in Advanced Ads Plugin for WordPress
CVE-2025-13592
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 December 2025
What is CVE-2025-13592?
The Advanced Ads plugin for WordPress contains a vulnerability that allows authenticated attackers with editor-level permissions or higher to execute arbitrary code on the server through the 'change-ad__content' shortcode parameter. This weakness affects versions up to and including 2.0.14, making it crucial for users to update the plugin to safeguard their systems against potential exploitation.
Affected Version(s)
Advanced Ads – Ad Manager & AdSense 0 <= 2.0.14