WordPress · Ad Inserter · CVE-2026-11983
**Name of the Vulnerable Software and Affected Versions**
Ad Inserter – Ad Manager & AdSense Ads versions prior to 2.8.17
**Description**
An authorization bypass exists due to a missing capability check in the `ai ajax` function. This flaw allows unauthenticated attackers to view the contents of ad blocks that were restricted by an administrator to be visible only to administrators.
**Recommendations**
Update Ad Inserter – Ad Manager & AdSense Ads to version 2.8.17 or later.
As a temporary workaround, restrict access to the `ai ajax` function to minimize the risk of exploitation.