Ad Inserter – Ad Manager & AdSense Ads
ad-inserter · plugin
Known security vulnerabilities for Ad Inserter – Ad Manager & AdSense Ads. Find out in seconds which version runs on your site with WP Lens.
14 known vulnerabilities
10 exploitable without logging in · latest Oct 1, 2026
Listed on wordpress.org · latest 2.8.19 · last updated Sep 23, 2026 · 300K+ installs
wordpress.org status checked on Oct 4, 2026
Vulnerabilities
- High 8.8
CVE-2019-15324login required
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
- High 7.5
CVE-2023-4668unauthenticated≤ 2.7.30
Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai-debug-processing-fe
- High 7.5
CVE-2019-15323unauthenticated
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
- High 7.1
CVE-2026-97077unauthenticated · needs a click≤ 2.8.18
WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2024-49248unauthenticated · needs a click≤ 2.7.37
WordPress Ad Inserter plugin <= 2.7.37 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-57693login required≤ 2.8.11
WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
CVE-2025-11745contributor+≤ 2.8.7
Ad Inserter <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
- Medium 6.1
CVE-2026-89427unauthenticated · needs a click≤ 2.8.18
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter
- Medium 6.1
CVE-2026-19902unauthenticated · needs a click≤ 2.8.18
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
- Medium 6.1
CVE-2026-9280unauthenticated · needs a click≤ 2.8.15
Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
- Medium 5.3
CVE-2026-11984unauthenticated≤ 2.8.16
Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter
- Medium 5.3
CVE-2023-4645unauthenticated≤ 2.7.30
Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai_ajax
- Medium 5.1
CVE-2025-22623unauthenticated · needs a click
Ad Inserter - Reflected cross-site scripting (XSS)
- Medium 4.3
CVE-2026-11900contributor+≤ 2.8.16
Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).