Scripteo operates a focused portfolio centered on WordPress advertising and promotion plugins, including Ads Pro and Ads Booster, that inject functionality into widely installed page-building environments. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the accessibility of plugin code to researchers and attackers; the recurring weakness classes include SQL injection, PHP remote file inclusion, and cross-site request forgery that are characteristic of server-side WordPress extensions. Defenders should apply plugin updates from this vendor promptly and monitor for exploitation of its advertising infrastructure, as live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scripteo over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4380CRITICAL The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_ | Jul 2, 2025 | 9.8 | 55 | NO | YES |
CVE-2024-13322HIGH The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, | May 2, 2025 | 7.5 | 35 | NO | YES |
CVE-2025-4689CRITICAL The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up | Jul 2, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-52428CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro all | Nov 18, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-6459HIGH The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.89. This i | Jul 2, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-6437HIGH The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘oid’ parameter in all versions up to, and including, 4 | Jul 2, 2025 | 7.5 | 23 | NO | NO |
CVE-2025-5339HIGH The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions up to | Jul 2, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-4381HIGH The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function in all versio | Jul 2, 2025 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scripteo.
Media articles that mention a CVE ID that affects a product developed by Scripteo — matched by CVE ID, not by vendor name.