PT-2026-103716 · WordPress · Ad Inserter
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ad Inserter – Ad Manager & AdSense Ads versions prior to 2.8.19
Description
Reflected Cross-Site Scripting is possible via the Referer header due to insufficient input sanitization and output escaping on the
{search-query} dynamic tag. The replace ai tags() function reads $ SERVER['HTTP REFERER'] and validates it using a regular expression. Because the regex allows a literal slash, any referrer containing a segment like '/google.com/' is accepted as a search-engine referral. The plugin then uses parse str() to decode the query and substitutes the q or p values into the ad block via preg replace() without escaping. This allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including administrators, by directing them to a malicious page that links to or frames a post. This requires an ad block to be configured with the {search-query} tag and automatic insertion enabled.Recommendations
Update Ad Inserter – Ad Manager & AdSense Ads to version 2.8.19 or later.
As a temporary workaround, avoid using the
{search-query} tag in ad blocks until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ad Inserter