PT-2026-99490 · WordPress · Ad Inserter
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ad Inserter WordPress plugin versions prior to 2.8.19
Description
Insufficient access restrictions on a settings page allow any logged-in user, including those with the subscriber role, to access the page under certain configurations. The plugin fails to filter content saved on this page, enabling users to store malicious code that is subsequently executed as PHP or served unescaped to site visitors.
Recommendations
Update Ad Inserter WordPress plugin to version 2.8.19 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ad Inserter