CVE-2026-39698 MEDIUM

CVE-2026-39698: WordPress The Publisher Desk ads.txt plugin <= 1.5.0 - Broken Access Control vulnerability

Vendor Publisherdesk
Product The Publisher Desk ads.txt
Weakness CWE-862 · Missing authorization
Published April 8, 2026
Last update April 29, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in PublisherDesk The Publisher Desk ads.txt the-publisher-desk-ads-txt allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Publisher Desk ads.txt: from n/a through <= 1.5.0.

Explanation of Vulnerability in Simple Terms

02Summary

The Publisher Desk ads.txt plugin through version 1.5.0 lacks proper authorization checks, allowing unauthenticated attackers to modify ads.txt configuration. An attacker can alter ad network settings without needing to log in or interact with a site administrator. This affects the integrity of ad serving and may allow injection of unauthorized ad networks or removal of legitimate ones.

What an attacker can do

03Attacker Capabilities

Modify ads.txt configuration without authentication.

Potential impact on your site

04Site Impact

Attackers can inject unauthorized ad networks or alter ad serving rules, potentially redirecting ad revenue or serving malicious ads.

Conditions required to exploit

05Prerequisites

Network access to the site; no login or user interaction required.

Key dates

06Disclosure timeline

April 8, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE