cleantalk
Vulnerabilities and Security Researches

Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads, CVE-2026-89050

CVE, Research URL

CVE-2026-89050

Published on
Sep 14, 2026
Research Description
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
Affected versions
max 3.0.5.
Status
vulnerable