Ad Inserter exposes disabled header and footer code through public debugging
Through 2.8.16, an unauthenticated requester can use the ai-debug-code URL parameter to retrieve administrator-configured header and footer code, including disabled blocks, because the debugging path lacks a capability check. The useful chaining primitive is disclosure of otherwise hidden configuration content; the export does not establish that every installation stores secrets there. The official 2.8.17 changelog explicitly fixes unauthenticated header/footer code disclosure.
- Component
- Ad Inserter – Ad Manager & AdSense Ads
- Plugin slug
ad-inserter- Affected
- <= 2.8.16
- Safe version
2.8.17- Published
- Sep 16, 2026
- Weakness
- CWE-862 — Missing Authorization
This CVE was published Sep 16, 2026 and is one of 17 known issues for this plugin.
Update, patch or deactivate.
Update Ad Inserter to 2.8.17 or later. Require an appropriate administrator capability before returning debug code and omit disabled or sensitive blocks from public responses. Review any exposed configuration and rotate credentials only if the disclosed content actually contained them.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter. This makes it possible for unauthenticated attackers to view administrator-configured header and footer code blocks that have been disabled from public display.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N