Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4380


The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site.


Published

2025-07-02T04:15:52.710

Last Modified

2025-07-08T14:34:59.070

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-98

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application scripteo ads_pro ≤ 4.89 Yes

References