Unauthenticated Broken Access Control in Ad Invalid Click Protector Plugin
CVE-2026-65445

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65445?

The Ad Invalid Click Protector plugin for WordPress has been identified to have an unauthenticated broken access control vulnerability. This flaw affects versions 1.3.0 and earlier, allowing unauthorized users to exploit the system and potentially access sensitive functions without proper authentication. It is crucial for site administrators using this plugin to assess their security measures and implement the latest patches to safeguard against potential attacks.

Affected Version(s)

Ad Invalid Click Protector (AICP) <= 1.3.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.