CVE-2026-89050: Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Quads Ads Manager for Google AdSense (WordPress plugin)to a version that resolves this vulnerability.Fixed in 3.0.5 - Compensating control
Ensure ad-selling order status is only marked as paid after verifying payment completion with the configured payment gateway (block or delay fulfillment until payment verification succeeds).
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who can place an ad-selling order can exploit it. The affected access level is Subscriber or higher.
What does an attacker need to do?
The attacker needs to submit an ad-selling order and use an unverified success return URL. Payment does not need to be completed for the order to be marked as paid.
What is the practical impact?
An attacker can obtain a paid ad placement without paying. The reported impact is limited to integrity, with no reported confidentiality or availability impact.
Which versions should be remediated?
Versions earlier than 3.0.5 are affected. Update the Quads Ads Manager for Google AdSense plugin to version 3.0.5 or later.