PT-2026-103716 · WordPress · Ad Inserter

·

CVE-2026-19902

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ad Inserter – Ad Manager & AdSense Ads versions prior to 2.8.19
Description Reflected Cross-Site Scripting is possible via the Referer header due to insufficient input sanitization and output escaping on the {search-query} dynamic tag. The replace ai tags() function reads $ SERVER['HTTP REFERER'] and validates it using a regular expression. Because the regex allows a literal slash, any referrer containing a segment like '/google.com/' is accepted as a search-engine referral. The plugin then uses parse str() to decode the query and substitutes the q or p values into the ad block via preg replace() without escaping. This allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including administrators, by directing them to a malicious page that links to or frames a post. This requires an ad block to be configured with the {search-query} tag and automatic insertion enabled.
Recommendations Update Ad Inserter – Ad Manager & AdSense Ads to version 2.8.19 or later. As a temporary workaround, avoid using the {search-query} tag in ad blocks until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19902

Affected Products

Ad Inserter