plugin

Ad Inserter Vulnerabilities

37 known security issues reported for the Ad Inserter WordPress plugin. Most recent disclosed Aug 5, 2026.

5 high 12 medium

Running Ad Inserter on your site? Check whether your installed version is affected.

Scan your site free

Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has...

CVSS:
5.3
Affected:
up to 2.8.16
Fixed in:
2.8.17
Disclosed:
Aug 5, 2026

CVE-2026-11983 on NVD →

Ad Inserter – Ad Manager & AdSense Ads <= 2.8.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrar...

CVSS:
6.4
Affected:
up to 2.8.11
Fixed in:
2.8.12
Disclosed:
Jul 8, 2026

CVE-2026-57693 on NVD →

Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_ai_tags() function processing a {reusable-block-N} tag pattern that calls get_post_f...

CVSS:
4.3
Affected:
up to 2.8.16
Fixed in:
2.8.17
Disclosed:
Jul 2, 2026

CVE-2026-11900 on NVD →

Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...

CVSS:
6.1
Affected:
up to 2.8.15
Fixed in:
2.8.16
Disclosed:
Jun 5, 2026

CVE-2026-9280 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.8.8

unknown

[en] The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Nov 5, 2025

CVE-2025-11745 on NVD →

Ad Inserter <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...

CVSS:
6.4
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Nov 4, 2025

CVE-2025-11745 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.8.1

unknown

[en] Ad Inserter - Ad Manager and AdSense Ads 2.8.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/includes/dst/dst.php.

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Mar 6, 2025

CVE-2025-22623 on NVD →

Ad Inserter - Ad Manager and AdSense Ads <= 2.8.0 - Reflected Cross-Site Scripting

medium

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 2.8.0
Fixed in:
2.8.1
Disclosed:
Mar 5, 2025

CVE-2025-22623 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.38

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Igor Funa Ad Inserter allows Reflected XSS.This issue affects Ad Inserter: from n/a through 2.7.37.

Affected:
up to 2.7.38
Fixed in:
2.7.38
Disclosed:
Oct 17, 2024

CVE-2024-49248 on NVD →

Ad Inserter <= 2.7.37 - Reflected Cross-Site Scripting

medium

The Ad Inserter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.37 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 2.7.37
Fixed in:
2.7.38
Disclosed:
Oct 14, 2024

CVE-2024-49248 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.31

unknown

[en] The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin sett...

Affected:
up to 2.7.31
Fixed in:
2.7.31
Disclosed:
Oct 20, 2023

CVE-2023-4668 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.31

unknown

[en] The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), username...

Affected:
up to 2.7.31
Fixed in:
2.7.31
Disclosed:
Oct 19, 2023

CVE-2023-4645 on NVD →

Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai_ajax

medium

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This can allow unauthenticated attackers to extract sensitive data such as post titles and slugs (including those of protected posts along with their passwords), usernames, av...

CVSS:
5.3
Affected:
up to 2.7.30
Fixed in:
2.7.31
Disclosed:
Sep 22, 2023

CVE-2023-4645 on NVD →

Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai-debug-processing-fe

medium

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings,...

CVSS:
5.3
Affected:
up to 2.7.30
Fixed in:
2.7.31
Disclosed:
Sep 22, 2023

CVE-2023-4668 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.27

unknown

[en] The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

Affected:
up to 2.7.27
Fixed in:
2.7.27
Disclosed:
May 15, 2023

CVE-2023-1549 on NVD →

Ad Inserter <= 2.7.25 - Authenticated (Admin+) PHP Object Injection

high

The Ad Inserter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.25 via deserialization of untrusted input from the $exported_settings variable when importing settings. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP cha...

CVSS:
7.2
Affected:
up to 2.7.25
Fixed in:
2.7.26
Disclosed:
Apr 19, 2023

CVE-2023-1549 on NVD →

Ad Inserter Free and Pro <= 2.7.11 - Reflected Cross-Site Scripting

medium

The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

CVSS:
6.1
Affected:
up to 2.7.12
Fixed in:
2.7.12
Disclosed:
Apr 7, 2022

CVE-2022-0901 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.12

unknown

[en] The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

Affected:
up to 2.7.12
Fixed in:
2.7.12
Disclosed:
Apr 4, 2022

CVE-2022-0901 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.12

unknown

[en] The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.7.12
Fixed in:
2.7.12
Disclosed:
Feb 21, 2022

CVE-2022-0288 on NVD →

Ad Inserter < 2.7.11 - Authenticated (Admin+) Remote Code Execution

high

The Ad Inserter plugin for WordPress is vulnerable to Remote Code Execution in versions before 2.7.11 via the settings.php file. This allows authenticated attackers with admin-level privileges to execute code on the server as well as perform stored cross-site scripting attacks.

CVSS:
7.2
Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
Feb 3, 2022

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.11

unknown

Admin+ RCE / Stored XSS vulnerability discovered by Viktor Markopoulos in WordPress Ad Inserter plugin (versions <= 2.7.10).

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
Feb 3, 2022

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.11

unknown

The Ad Inserter plugin for WordPress is vulnerable to Remote Code Execution in versions before 2.7.11 via the settings.php file. This allows authenticated attackers with admin-level privileges to execute code on the server as well as perform stored cross-site scripting attacks.

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
Feb 3, 2022

Ad Inserter <= 2.7.9 - Reflected Cross-Site Scripting

medium

The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.7.10
Fixed in:
2.7.10
Disclosed:
Jan 24, 2022

CVE-2022-0288 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 1.5.3

unknown

[en] The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Oct 22, 2019

CVE-2015-9497 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.4.22

unknown

[en] The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.

Affected:
up to 2.4.22
Fixed in:
2.4.22
Disclosed:
Aug 22, 2019

CVE-2019-15324 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.4.20

unknown

[en] The ad-inserter plugin before 2.4.20 for WordPress has path traversal.

Affected:
up to 2.4.20
Fixed in:
2.4.20
Disclosed:
Aug 22, 2019

CVE-2019-15323 on NVD →

Ad Inserter <= 2.4.21 - Authenticated Remote Code Execution

high

The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.

CVSS:
8.8
Affected:
up to 2.4.21
Fixed in:
2.4.22
Disclosed:
Jul 15, 2019

CVE-2019-15324 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.4.22

unknown

Authenticated Remote Code Execution (RCE) vulnerability found by Sean Murphy (WordFence) in WordPress Ad Inserter plugin (versions <= 2.4.21).

Affected:
up to 2.4.22
Fixed in:
2.4.22
Disclosed:
Jul 15, 2019

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.4.20

unknown

Authenticated Path Traversal vulnerability found by Wilfried Becard in WordPress Ad Inserter plugin (versions <= 2.4.19).

Affected:
up to 2.4.20
Fixed in:
2.4.20
Disclosed:
Jul 13, 2019

Ad Inserter <= 2.4.19 - Authenticated Path Traversal

high

The ad-inserter plugin before 2.4.20 for WordPress has path traversal.

CVSS:
7.5
Affected:
up to 2.4.19
Fixed in:
2.4.20
Disclosed:
Jul 12, 2019

CVE-2019-15323 on NVD →

Ad Inserter <= 1.5.5 - Cross-Site Request Forgery to Cross-Site Scripting

medium

The Ad Inserter plugin for WordPress is vulnerable to Cross-Site Scripting via the 'ai-active-tab' parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
4.8
Affected:
up to 1.5.5
Fixed in:
1.5.6
Disclosed:
Aug 13, 2015

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 1.5.6

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 13, 2015

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 1.5.6

unknown

The Ad Inserter plugin for WordPress is vulnerable to Cross-Site Scripting via the 'ai-active-tab' parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 13, 2015

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 1.5.3

unknown

CSRF vulnerability allows an attacker to insert an arbitrary script into admin page. After that an attacker can do almost anything on the admin's browser. Update to Latest version 1.5.3.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
May 8, 2015

Ad Inserter – Ad Manager & AdSense Ads < 1.5.3 - Cross-Site Request Forgery to Cross-Site Scripting

high

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

CVSS:
8.8
Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
May 2, 2015

CVE-2015-9497 on NVD →

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 2.7.11

unknown
Affected:
up to 2.7.11
Fixed in:
2.7.11

Ad Inserter &#8211; Ad Manager &amp; AdSense Ads [ad-inserter] < 1.5.6

unknown

The Ad Inserter &ndash; Ad Manager &amp; AdSense Ads WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.5.6
Fixed in:
1.5.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database