Description
WordPress Plugin Ads for WP-Advanced Ads & Adsense Solution for WP & AMP is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Ads for WP-Advanced Ads & Adsense Solution for WP & AMP version 1.8 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that CSRF protection is implemented with Nonce-like mechanism or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Contact Form DB-Elementor Cross-Site Scripting (1.7)
MySQL CVE-2020-2752 Vulnerability (CVE-2020-2752)
Internet Information Services Improper Authentication Vulnerability (CVE-2009-1535)
Drupal Core 9.0.x Remote Code Execution (9.0.0 - 9.0.8)
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more PHAR Deserialization (2.9.8.5)