Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 2 are fixed and 9 remain unpatched as of September 2026. Their average CVSS score is 7.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 7 high. 2025 was the busiest year with 10 disclosures.

The most common weakness is SQL Injection, behind 5 of the records (45%). Other recurring categories include PHP Remote File Inclusion, Cross-Site Request Forgery (CSRF).

2 of the records (18%) have a vendor fix, while 9 remain unpatched. The oldest unresolved one dates back to 2025.

2 independent researchers contributed these findings, most of them (10) reported by Trương Hữu Phúc (truonghuuphuc).

Strategic Overview

Avg CVSSHigh
7.7/ 10
Patch Coverage18%
Open

9

Fixed

2

Get automatic notifications for all Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-4689

Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion to Remote Code Execution

Read the full analysis

Vulnerability Records

11 records
2026-02-20 00:00CVE-2026-25388
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2025-11-23 16:21CVE-2025-7402
7.5
High
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:54CVE-2025-5339
7.5
High
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:54CVE-2025-6437
7.5
High
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:53CVE-2025-6459
8.8
High
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:53CVE-2025-4381
7.5
High
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:53CVE-2025-4689
9.8
Critical
Trương Hữu Phúc (truonghuuphuc)No
2025-07-01 14:52CVE-2025-4380
8.1
High
Trương Hữu Phúc (truonghuuphuc)No
2025-05-21 00:00CVE-2025-46444
9.8
Critical
Nguyễn Trung KiênNo
2025-05-16 00:00CVE-2025-46464
6.4
Medium
Trương Hữu Phúc (truonghuuphuc)No
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C