HomeWordPress vulnerabilitiesAd Inserter
Ad Inserter vulnerabilities
Ad Inserter has 16 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.
- Known vulnerabilities
- 16
- Active installs
- 300,000+
- Latest version
- 2.8.19
- Last updated
- 23 Sep 2026
- Most recent
- 1 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-89427 | Medium 6.1 | Up to 2.8.18 | Fixed in a later version (latest 2.8.19) | 6 d ago |
| Cross-site scripting (XSS) CVE-2026-19902 | Medium 6.1 | Up to 2.8.18 | Fixed in a later version (latest 2.8.19) | 6 d ago |
| Remote code execution CVE-2026-81655 | High 7.5 | Before 2.8.19 | Fixed in 2.8.19 | 10 d ago |
| Broken access control CVE-2026-11984 | Medium 5.3 | Up to 2.8.16 | Fixed in a later version (latest 2.8.19) | 16 Sep 2026 |
| Broken access control CVE-2026-11983 | Medium 5.3 | Up to 2.8.16 | Fixed in a later version (latest 2.8.19) | 6 Aug 2026 |
| Broken access control CVE-2026-11900 | Medium 4.3 | Up to 2.8.16 | Fixed in a later version (latest 2.8.19) | 3 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-9280 | Medium 6.1 | Up to 2.8.15 | Fixed in a later version (latest 2.8.19) | 6 Jun 2026 |
| Cross-site scripting (XSS) CVE-2025-11745 | Medium 6.4 | Up to 2.8.7 | Fixed in a later version (latest 2.8.19) | 5 Nov 2025 |
| Sensitive data exposure CVE-2023-4668 | Medium 5.3 | Before 2.7.31 | Fixed in 2.7.31 | 20 Oct 2023 |
| Sensitive data exposure CVE-2023-4645 | Medium 5.3 | Up to 2.7.30 | Fixed in a later version (latest 2.8.19) | 19 Oct 2023 |
| PHP object injection CVE-2023-1549 | High 7.2 | Before 2.7.27 | Fixed in 2.7.27 | 15 May 2023 |
| Cross-site scripting (XSS) CVE-2022-0901 | Medium 6.1 | Before 2.7.12 | Fixed in 2.7.12 | 4 Apr 2022 |
| Cross-site scripting (XSS) CVE-2022-0288 | Medium 6.1 | Before 2.7.10 | Fixed in 2.7.10 | 21 Feb 2022 |
| Cross-site scripting (XSS) CVE-2015-9497 | High 8.8 | Before 1.5.3 | Fixed in 1.5.3 | 22 Oct 2019 |
| Path traversal CVE-2019-15323 | High 7.5 | Before 2.4.20 | Fixed in 2.4.20 | 22 Aug 2019 |
| Remote code execution CVE-2019-15324 | High 8.8 | Before 2.4.22 | Fixed in 2.4.22 | 22 Aug 2019 |
Read the published descriptions
- CVE-2026-89427, 1 Oct 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature. CVE record
- CVE-2026-19902, 1 Oct 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled - a documented plugin feature used as intended. CVE record
- CVE-2026-81655, 27 Sep 2026
- The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors. CVE record
- CVE-2026-11984, 16 Sep 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter. This makes it possible for unauthenticated attackers to view administrator-configured header and footer code blocks that have been disabled from public display. CVE record
- CVE-2026-11983, 6 Aug 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility. CVE record
- CVE-2026-11900, 3 Jul 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_ai_tags() function processing a {reusable-block-N} tag pattern that calls get_post_field('post_content', N) without verifying the requesting user's capability with current_user_can('read_post'), without restricting the post type to 'wp_block', and without checking the post status. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the full content of arbitrary posts including Private, Draft, Pending, Trashed, and password-protected posts owned by other users, by placing the shortcode in a post they own and previewing it. CVE record
- CVE-2026-9280, 6 Jun 2026
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that iframe mode (AI_OPTION_IFRAME) is enabled on at least one ad block displayed on the targeted page, which is a non-default but supported configuration commonly used for AdSense and JavaScript-based ads. CVE record
- CVE-2025-11745, 5 Nov 2025
- The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-4668, 20 Oct 2023
- The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths. CVE record
- CVE-2023-4645, 19 Oct 2023
- The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, available roles, the plugin license key provided the remote debugging option is enabled. In the default state it is disabled. CVE record
- CVE-2023-1549, 15 May 2023
- The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present CVE record
- CVE-2022-0901, 4 Apr 2022
- The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters CVE record
- CVE-2022-0288, 21 Feb 2022
- The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting CVE record
- CVE-2015-9497, 22 Oct 2019
- The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. CVE record
- CVE-2019-15323, 22 Aug 2019
- The ad-inserter plugin before 2.4.20 for WordPress has path traversal. CVE record
- CVE-2019-15324, 22 Aug 2019
- The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. CVE record
What to do if you run Ad Inserter
If you run Ad Inserter, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Ad Inserter vulnerabilities
Free. We email you when a new vulnerability is published for Ad Inserter, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.