Broken Access Control in WPQuads Plugin for WordPress
CVE-2026-57335

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 June 2026

What is CVE-2026-57335?

The Ads by WPQuads plugin for WordPress, especially in versions up to 3.0.3, exhibits a broken access control vulnerability. This issue could allow unauthorized users to access restricted functionality, potentially leading to data leaks or misuse of resources. Site administrators should enforce strict access permissions and apply security updates to mitigate potential threats.

Affected Version(s)

Ads by WPQuads <= 3.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.