CVE-2026-89050: Unknown Quads Ads Manager For Google Adsense

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

Affected products

  • Unknown Quads Ads Manager For Google Adsense: from 3.0.4, before 3.0.5 (fixed in 3.0.5)

Published 2026-09-13. Last modified 2026-09-14.