The Moneytizer
The Moneytizer has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 4 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (40%). Other recurring categories include Improper Access Control, Missing Authorization.
4 of the records (80%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
4 independent researchers contributed these findings, most of them (2) reported by Francesco Carlucci. The Moneytizer is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-39685The Moneytizer <= 10.0.10 - Missing Authorization
Read the full analysisVulnerability Records
The Moneytizer
Author
lvaudore
The Moneytizer is an advertising platform which enables you to monetize your website very easily. Manage your ad units and start displaying the great campaigns. Plus, you can follow your daily statistics on our dashboard.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C