CVE-2026-2595Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1 due to insufficient input sanitization and output escaping of multiple ad metadata parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-29: 1Technical Details · 2026-03-28: 203-2803-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-282
Disclosure2
2026-03-291
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2595 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2595 #CVE-2026-2595 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/fZgSWpQHca

    Post summary

    Announcement of CVE‑2026‑2595, a medium‑severity vulnerability affecting WordPress, with no further technical, exploit, or mitigation details provided.

    0000030
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2595 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1 due to insufficien… https://www.cve.org/CVERecord?id=CVE-2026-2595

    Post summary

    CVE-2026-2595 exposes a stored XSS flaw in the Quads Ads Manager for Google AdSense WordPress plugin (v2.0.98.1 and earlier), as noted in the CVE record.

    0000087
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2595 - Quads Ads Manager for Google AdSense <= 2.0.98.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Ad Metadata Parameters Intel Report: https://ift.tt/X4C92xw

    Post summary

    A new CVE (CVE-2026-2595) is disclosed, describing an authenticated Contributor+ stored XSS in Quads Ads Manager, with no PoC, exploitation, or patch information provided.

    0000031
    283 followersView on X

Explore more