Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesAd Inserter

Ad Inserter vulnerabilities

Ad Inserter has 16 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
16
Active installs
300,000+
Latest version
2.8.19
Last updated
23 Sep 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-89427
Medium 6.1Up to 2.8.18Fixed in a later version (latest 2.8.19)6 d ago
Cross-site scripting (XSS)
CVE-2026-19902
Medium 6.1Up to 2.8.18Fixed in a later version (latest 2.8.19)6 d ago
Remote code execution
CVE-2026-81655
High 7.5Before 2.8.19Fixed in 2.8.1910 d ago
Broken access control
CVE-2026-11984
Medium 5.3Up to 2.8.16Fixed in a later version (latest 2.8.19)16 Sep 2026
Broken access control
CVE-2026-11983
Medium 5.3Up to 2.8.16Fixed in a later version (latest 2.8.19)6 Aug 2026
Broken access control
CVE-2026-11900
Medium 4.3Up to 2.8.16Fixed in a later version (latest 2.8.19)3 Jul 2026
Cross-site scripting (XSS)
CVE-2026-9280
Medium 6.1Up to 2.8.15Fixed in a later version (latest 2.8.19)6 Jun 2026
Cross-site scripting (XSS)
CVE-2025-11745
Medium 6.4Up to 2.8.7Fixed in a later version (latest 2.8.19)5 Nov 2025
Sensitive data exposure
CVE-2023-4668
Medium 5.3Before 2.7.31Fixed in 2.7.3120 Oct 2023
Sensitive data exposure
CVE-2023-4645
Medium 5.3Up to 2.7.30Fixed in a later version (latest 2.8.19)19 Oct 2023
PHP object injection
CVE-2023-1549
High 7.2Before 2.7.27Fixed in 2.7.2715 May 2023
Cross-site scripting (XSS)
CVE-2022-0901
Medium 6.1Before 2.7.12Fixed in 2.7.124 Apr 2022
Cross-site scripting (XSS)
CVE-2022-0288
Medium 6.1Before 2.7.10Fixed in 2.7.1021 Feb 2022
Cross-site scripting (XSS)
CVE-2015-9497
High 8.8Before 1.5.3Fixed in 1.5.322 Oct 2019
Path traversal
CVE-2019-15323
High 7.5Before 2.4.20Fixed in 2.4.2022 Aug 2019
Remote code execution
CVE-2019-15324
High 8.8Before 2.4.22Fixed in 2.4.2222 Aug 2019
Read the published descriptions
CVE-2026-89427, 1 Oct 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature. CVE record
CVE-2026-19902, 1 Oct 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled - a documented plugin feature used as intended. CVE record
CVE-2026-81655, 27 Sep 2026
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors. CVE record
CVE-2026-11984, 16 Sep 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter. This makes it possible for unauthenticated attackers to view administrator-configured header and footer code blocks that have been disabled from public display. CVE record
CVE-2026-11983, 6 Aug 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility. CVE record
CVE-2026-11900, 3 Jul 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_ai_tags() function processing a {reusable-block-N} tag pattern that calls get_post_field('post_content', N) without verifying the requesting user's capability with current_user_can('read_post'), without restricting the post type to 'wp_block', and without checking the post status. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the full content of arbitrary posts including Private, Draft, Pending, Trashed, and password-protected posts owned by other users, by placing the shortcode in a post they own and previewing it. CVE record
CVE-2026-9280, 6 Jun 2026
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that iframe mode (AI_OPTION_IFRAME) is enabled on at least one ad block displayed on the targeted page, which is a non-default but supported configuration commonly used for AdSense and JavaScript-based ads. CVE record
CVE-2025-11745, 5 Nov 2025
The Ad Inserter - Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-4668, 20 Oct 2023
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths. CVE record
CVE-2023-4645, 19 Oct 2023
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, available roles, the plugin license key provided the remote debugging option is enabled. In the default state it is disabled. CVE record
CVE-2023-1549, 15 May 2023
The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present CVE record
CVE-2022-0901, 4 Apr 2022
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters CVE record
CVE-2022-0288, 21 Feb 2022
The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting CVE record
CVE-2015-9497, 22 Oct 2019
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. CVE record
CVE-2019-15323, 22 Aug 2019
The ad-inserter plugin before 2.4.20 for WordPress has path traversal. CVE record
CVE-2019-15324, 22 Aug 2019
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. CVE record

What to do if you run Ad Inserter

If you run Ad Inserter, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Ad Inserter vulnerabilities

Free. We email you when a new vulnerability is published for Ad Inserter, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support