Access violation vulnerability in AdFoxly – Ad Manager, AdSense Ads & Ads.txt 1.8.5

The AdFoxly plugin for WordPress, which is used for managing ads and displaying AdSense ads, has a security issue where data can be changed without permission. This is because the adfoxly_ad_status() function in all versions up to 1.8.5 does not have a check to ensure that the user has the proper capabilities. This means that attackers who are not logged in can turn ads on and off without authorization.

Detected in:

AdFoxly – Ad Manager, AdSense Ads & Ads.txt open vulnerable versions: > 0 < 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.