Sceawere

Vulnerability Detail

CVE-2025-15643UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Adsmonetizer Adsensei-b30

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Jose Fernandez
Product
Adsmonetizer
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-05T18:17:28.767Z",
  "pubdate": "2026-10-05T18:17:28.767Z",
  "executiveSummary": "The Adsensei-b30 plugin for WordPress, developed by Adsmonetizer, contains a vulnerability classified as Improper Neutralization of Input During Web Page Generation, commonly referred to as Cross-site Scripting (XSS).\nThis vulnerability is classified as a Reflected XSS flaw, which occurs when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner.\nThe affected versions include Adsmonetizer Adsensei-b30 from n/a through 3.2.4.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject malicious client-side scripts into the victim's browser session. If executed, the script operates within the security context of the vulnerable site, potentially leading to unauthorized actions, session hijacking, credential theft, or the redirection of users to malicious third-party domains.\nBecause the payload is reflected via the web server, the impact is primarily directed at the end-user. The vulnerability poses a significant risk to site integrity and user trust if exploited by attackers to distribute malware or compromise administrative sessions.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of user-supplied HTTP request parameters by the Adsensei-b30 plugin. When the plugin processes incoming requests, it fails to sufficiently sanitize or validate input before reflecting it back to the client in the HTML response. This deficiency in input neutralization creates an injection vector where an attacker can supply arbitrary JavaScript payloads.\nThe attack flow initiates when an attacker crafts a malicious URL containing a payload within a vulnerable parameter. This URL is then distributed to a target user, often via social engineering, phishing, or by embedding the link on a third-party site. When the victim clicks the link, the browser sends an HTTP request containing the malicious payload to the server running the vulnerable version of Adsensei-b30.\nThe application processes the request and incorporates the unsanitized input directly into the generated HTML body. Consequently, the victim's web browser renders the server response and executes the injected script. Because the script originates from a trusted domain, it may bypass certain browser-based security controls, allowing the attacker to perform actions on behalf of the user, such as modifying page content, capturing sensitive cookies, or performing background API requests.\nThe vulnerability is present in versions up to and including 3.2.4. Exploitation does not typically require high-level privileges; the reflected nature of the attack means that any user, including unauthenticated visitors, can be targeted if they can be induced to interact with the malicious URL. The execution occurs entirely on the client side, leveraging the victim's session to maximize the impact of the injected script.\nPost-exploitation impact varies depending on the nature of the script injected. In environments where administrators or users with elevated privileges are targeted, the vulnerability can be leveraged to hijack active administrative sessions, modify plugin configurations, or inject persistent backdoors into the WordPress installation. Furthermore, the lack of input neutralization allows for the bypass of standard server-side security filters, making the identification of such reflected payloads difficult without robust input validation and output encoding mechanisms in place at the application layer."
}
CVE-2025-15643: Reflected XSS in Adsmonetizer Adsensei-b30 (HIGH Severity, CVSS: 7.1) | Sceawere