CVE-2025-13592: Monetizemore Advanced Ads – Ad Manager & Adsense

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This allows authenticated attackers with editor-level permissions or above, to execute code on the server.

Affected products

  • Monetizemore Advanced Ads – Ad Manager & Adsense: up to and including 2.0.14

Published 2025-12-29. Last modified 2026-10-07.