Payment Verification Bypass in Quads Ads Manager for Google AdSense Plugin
CVE-2026-89050
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-89050?
The Quads Ads Manager for Google AdSense plugin prior to version 3.0.5 contains a security flaw that allows users to mark an ad-selling order as paid without verifying the completion of the payment through the configured payment gateway. This vulnerability poses a risk as it enables unauthorized ad placements, allowing individuals who can place orders to exploit the system and gain access to paid advertising without proper payment verification.
Affected Version(s)
Quads Ads Manager for Google AdSense 3.0.4 < 3.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved