CVE-2025-5339

CVE-2025-5339 identifies a critical time-based SQL Injection vulnerability within the WordPress Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager.

Executive summary

CVE-2025-5339 identifies a critical time-based SQL Injection vulnerability within the WordPress Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager. This flaw specifically affects all versions up to and including 4.0 and is exploitable via the 'bsa_pro_id' parameter.