CVE-2025-15643: WordPress Adsmonetizer plugin <= 3.2.4 - Cross Site Scripting (XSS) vulnerability
Published Oct 5, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4.
Affected Software
1 affected component
Jose Fernandez Adsmonetizer<=3.2.4
Event History
Oct 5, 2026
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or special access to exploit this issue?
No privileges are required, and the attack vector is network-based with low attack complexity. Exploitation does require user interaction.
2
What is the expected impact if exploitation succeeds?
The severity is rated high with a 7.1 score. The CVSS vector indicates low impact to confidentiality, integrity, and availability, with scope changed.