CVE-2025-13592EPSS p57.3%
CVE-2025-13592CVE-2025-13592
Description
The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This allows authenticated attackers with editor-level permissions or above, to execute code on the server.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.86% probability of exploitation · percentile 57.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |