Two vulnerabilities have been discovered in the Ads Pro Plugin for WordPress. These vulnerabilities, CVE-2025-46444 (LFI) and CVE-2025-46464 (XSS), pose a significant risk to websites using the plugin. A patch is available via plugin update.
CVE-2025-46444 has a critical CVSS score of 9.8, indicating a high risk of remote code execution.
What is Ap Plugin Scripteo?
CVE-2025-46444: Unauthenticated Local File Inclusion in Ads Pro Plugin
Critical: Allows unauthenticated remote code execution.
EPSS score of 0.547 suggests moderate exploitability.
The Ads Pro Plugin is vulnerable to Local File Inclusion (LFI). An unauthenticated attacker can include and execute arbitrary files on the server, potentially leading to remote code execution.
How to fix CVE-2025-46444 in Ap Plugin Scripteo
Patch immediately- 1.Update the Ads Pro Plugin to the latest version.
wp plugin update ap-plugin-scripteoVerify with:
wp plugin listWorkaround: No known workaround is available. Immediate patching is highly recommended.
NextGuard automatically flags CVE-2025-46444 if Ap Plugin Scripteo appears in any of your monitored projects — no manual lookup required.
CVE-2025-46464: Authenticated Stored Cross-Site Scripting in Ads Pro Plugin
Medium: Requires authentication, but allows script injection.
EPSS score of 0.143 indicates low exploitability.
The Ads Pro Plugin is vulnerable to Stored Cross-Site Scripting (XSS). Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages.
How to fix CVE-2025-46464 in Ap Plugin Scripteo
Patch within 24h- 1.Update the Ads Pro Plugin to the latest version.
wp plugin update ap-plugin-scripteoVerify with:
wp plugin listWorkaround: Restrict contributor access and carefully review user-submitted content.
NextGuard automatically flags CVE-2025-46464 if Ap Plugin Scripteo appears in any of your monitored projects.
Stay ahead of WordPress vulnerabilities
Proactively identify and remediate WordPress vulnerabilities with continuous monitoring. monitor your wordpress dependencies.
Compare PlansFrequently asked questions
The Ads Pro Plugin vulnerabilities pose a significant risk to WordPress websites. Ensure you update to the latest version of the plugin to mitigate these risks and see all wordpress vulnerabilities.
Related topics