Unauthenticated SQL Injection Vulnerability in Advanced Ads Tracking Plugin by WordPress
CVE-2025-59554

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2025-59554?

An unauthenticated SQL injection vulnerability has been identified in versions of the Advanced Ads – Tracking plugin prior to 3.0.7. This flaw allows unauthorized attackers to execute arbitrary SQL commands, potentially leading to data leaks, unauthorized data manipulation, and complete takeover of the site's database. Website administrators are advised to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Advanced Ads – Tracking < 3.0.7

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AirBesta | Patchstack Bug Bounty Program
.