WordPress security changelog
MEDIUM CVE-2026-11984 Deferred

Ad Inserter exposes disabled header and footer code through public debugging

Through 2.8.16, an unauthenticated requester can use the ai-debug-code URL parameter to retrieve administrator-configured header and footer code, including disabled blocks, because the debugging path lacks a capability check. The useful chaining primitive is disclosure of otherwise hidden configuration content; the export does not establish that every installation stores secrets there. The official 2.8.17 changelog explicitly fixes unauthenticated header/footer code disclosure.

CVE / CNA score 5.3 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Ad Inserter – Ad Manager & AdSense Ads
Plugin slug
ad-inserter
Affected
<= 2.8.16
Safe version
2.8.17
Published
Sep 16, 2026
Weakness
CWE-862 — Missing Authorization

This CVE was published Sep 16, 2026 and is one of 17 known issues for this plugin.

Update, patch or deactivate.

Update Ad Inserter to 2.8.17 or later. Require an appropriate administrator capability before returning debug code and omit disabled or sensitive blocks from public responses. Review any exposed configuration and rotate credentials only if the disclosed content actually contained them.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter. This makes it possible for unauthenticated attackers to view administrator-configured header and footer code blocks that have been disabled from public display.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Primary and upstream sources