Ad Inserter
Ad Inserter inserts advertisements, scripts, and other custom content into configurable locations across WordPress pages and posts.
Ad Inserter (ad-inserter) is a WordPress plugin with 17 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 8.8.
ad-inserterCVE-2026-19902: Ad Inserter – Ad Manager & AdSense Ads: Cross-site scripting
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-19902
Ad Inserter – Ad Manager & AdSense Ads: Cross-site scripting
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Sep 30, 2026 |
CVE-2026-97077
Ad Inserter: Cross-site scripting
Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. The reported impact is browser script execution in the affected site's origin. The injected field, rendering context and exact victim interaction are unspecified. The authoritative export does not identify the vulnerable endpoint, action, parameter or function, so the precise input-to-operation path cannot be established from this snapshot. The authoritative export identifies the fixed release as 2.8.19.
|
2.8.19 |
CVE7.1
NVDPending
|
| Sep 27, 2026 |
CVE-2026-81655
Ad Inserter: Subscriber-level stored PHP execution
Ad Inserter 2.8.12 through versions before 2.8.19 makes a settings page accessible to every logged-in user under a configuration permitted by its own settings and fails to filter saved content. A Subscriber or higher can store code that is later executed as PHP or served unescaped to site visitors. The settings-page route, option enabling access, input fields and execution function are unspecified. Exploitability is conditional on that access configuration, not established for the default setup.
|
2.8.19 |
CVE7.5
NVDPending
|
| Sep 16, 2026 |
CVE-2026-11984
Ad Inserter exposes disabled header and footer code through public debugging
Through 2.8.16, an unauthenticated requester can use the ai-debug-code URL parameter to retrieve administrator-configured header and footer code, including disabled blocks, because the debugging path lacks a capability check. The useful chaining primitive is disclosure of otherwise hidden configuration content; the export does not establish that every installation stores secrets there. The official 2.8.17 changelog explicitly fixes unauthenticated header/footer code disclosure.
|
2.8.17 |
CVE5.3
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57693
Ad Inserter: Cross-site scripting
Ad Inserter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.11.
|
2.8.12 |
CVE6.5
NVDPending
|
| Jul 03, 2026 |
CVE-2026-11900
Ad Inserter – Ad Manager & AdSense Ads: Broken access control
Ad Inserter – Ad Manager & AdSense Ads is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 2.8.16.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 06, 2026 |
CVE-2026-9280
Ad Inserter – Ad Manager & AdSense Ads: Cross-site scripting
Ad Inserter – Ad Manager & AdSense Ads is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.15.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Nov 05, 2025 |
CVE-2025-11745
Ad Inserter – Ad Manager & AdSense Ads: Cross-site scripting
Ad Inserter – Ad Manager & AdSense Ads is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 06, 2025 |
CVE-2025-22623
Ad Inserter: A security weakness
Ad Inserter is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.1
NVDPending
|
| Oct 17, 2024 |
CVE-2024-49248
Ad Inserter: Cross-site scripting
Ad Inserter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Oct 20, 2023 |
CVE-2023-4668
Ad Inserter: Sensitive information exposure
Ad Inserter is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Oct 19, 2023 |
CVE-2023-4645
Ad Inserter: Sensitive information exposure
Ad Inserter is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| May 15, 2023 |
CVE-2023-1549
Ad Inserter: Code execution
Ad Inserter is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Apr 04, 2022 |
CVE-2022-0901
Ad Inserter: Cross-site scripting
Ad Inserter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Oct 22, 2019 |
CVE-2015-9497
Ad Inserter: Cross-site scripting
Ad Inserter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Aug 22, 2019 |
CVE-2019-15324
Ad Inserter: Code execution
Ad Inserter is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Aug 22, 2019 |
CVE-2019-15323
Ad Inserter: Filesystem traversal
Ad Inserter is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD7.5
|