What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Google Adsense & Banner Ads by AdsforWP ads-for-wp allows Cross Site Request Forgery.This issue affects Google Adsense & Banner Ads by AdsforWP: from n/a through <= 1.9.28.
Explanation of Vulnerability in Simple Terms
02Summary
The Google Adsense & Banner Ads by AdsforWP plugin for WordPress versions 1.9.28 and earlier contains a cross-site request forgery (CSRF) vulnerability. An attacker can trick a logged-in site administrator into performing unintended actions, such as modifying ad settings or plugin configuration, by sending them a malicious link or embedding code on a webpage. The vulnerability requires the admin to click the link or visit the attacker's page while logged into WordPress.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into changing plugin settings or ad configuration without their knowledge.
Potential impact on your site
04Site Impact
Ad settings or plugin configuration could be altered by an attacker without your consent or knowledge.
Conditions required to exploit
05Prerequisites
Admin must be logged into WordPress and click a malicious link or visit attacker-controlled page.
Key dates
06Disclosure timeline
January 2, 2025
CVE published
April 28, 2026
Record updated