Ad Buttons
Ad Buttons has one disclosed vulnerability in the WordSec catalog, all reported in 2015; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Ad Buttons has a vendor fix available, so running the current release closes it.
All of these findings were reported by Kaustubh G. Padwad. Ad Buttons is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2017-18553Ad Buttons <= 2.3.1 - Cross-Site Request Forgery to Cross-Site Scripting
Read the full analysisVulnerability Records
Ad Buttons
Author
mindnl
The Ad Buttons plugin displays a number of graphical ads in a sidebar widget The current version contains the following functionality: Add new ad buttons: By entering image URL, link URL and link text a new ad button will be created Enable/disable individual ad buttons: Each ad button can be enabled or disabled from the admin panel Select how many ad buttons to display in the sidebar widget. Displaying the ad buttons on your blog is done by randomly selecting ads from your total list of active ads. You can select how many ads are displayed on your blog. See how many times each ad button has been displayed and clicked. Ad performance is an important measurement, especially when your ads link to affiliate programs. The number of views, clicks and CTR (click thru rate) are displayed for each ad button. Views by search engine bots are automatically filtered from the count. A Google AdSense 125 x 125 ad unit can be displayed by filling in your AdSense publisher ID. AdSense ad colors can be controlled right from the Ad Buttons admin panel.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C