ViaAds
ViaAds has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for ViaAds has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. ViaAds is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-12070ViaAds <= 2.1.2 - Cross-Site Request Forgery to API Key Update
Read the full analysisVulnerability Records

ViaAds
Author
Valyrion
ViaAds plugin is what enables ViaAds, to receive data regarding orders and behavior of the customers on the merchant website, which is then used by ViaAds to create marketing material for the merchant that redirects the customer to the merchants website, thus creating increased traffic and sales. ViaAds plugin enables automatic withdrawel of required order and behavior data, so that the customer doesn’t need to deliver the data for marketing to ViaAds, as the plugin tracks and sends the data automatically. This plugin is required by the webshop in order to enroll in the ViaAds marketing solutions from ViaBill. The plugin allows for the registration and import of your products, orders, and refund data, which will then be used to send existing as well as new customer from the ViaBill network to your webshop, hereby increasing traffic and sales. This is done through profiling and segmentation of customers in order to understand behavioral connections and customer preferences. This allows ViaAds to propose specific products to each individual ViaBill customer in a scalable manner. This marketing wil be carried out by contacting the customer with relevant products form your webshop via e-mail, push notifications, ads on My ViaBill, ads in the ViaBill app, pop-up messages in the ViaBill app, as well as the shop overview in the ViaBill app.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C