PT-2026-99490 · WordPress · Ad Inserter

·

CVE-2026-81655

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ad Inserter WordPress plugin versions prior to 2.8.19
Description Insufficient access restrictions on a settings page allow any logged-in user, including those with the subscriber role, to access the page under certain configurations. The plugin fails to filter content saved on this page, enabling users to store malicious code that is subsequently executed as PHP or served unescaped to site visitors.
Recommendations Update Ad Inserter WordPress plugin to version 2.8.19 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81655

Affected Products

Ad Inserter