Unauthenticated Broken Access Control in Ad Invalid Click Protector Plugin
CVE-2026-65445
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-65445?
The Ad Invalid Click Protector plugin for WordPress has been identified to have an unauthenticated broken access control vulnerability. This flaw affects versions 1.3.0 and earlier, allowing unauthorized users to exploit the system and potentially access sensitive functions without proper authentication. It is crucial for site administrators using this plugin to assess their security measures and implement the latest patches to safeguard against potential attacks.
Affected Version(s)
Ad Invalid Click Protector (AICP) <= 1.3.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program