Skip to content
Noroxi

Ad Inserter – Ad Manager & AdSense Ads

ad-inserter · plugin

Known security vulnerabilities for Ad Inserter – Ad Manager & AdSense Ads. Find out in seconds which version runs on your site with WP Lens.

14 known vulnerabilities

10 exploitable without logging in · latest Oct 1, 2026

Listed on wordpress.org · latest 2.8.19 · last updated Sep 23, 2026 · 300K+ installs

wordpress.org status checked on Oct 4, 2026

Vulnerabilities

  • CVE-2019-15324login required

    The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.

    High 8.8
  • CVE-2023-4668unauthenticated≤ 2.7.30

    Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai-debug-processing-fe

    High 7.5
  • CVE-2019-15323unauthenticated

    The ad-inserter plugin before 2.4.20 for WordPress has path traversal.

    High 7.5
  • CVE-2026-97077unauthenticated · needs a click≤ 2.8.18

    WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2024-49248unauthenticated · needs a click≤ 2.7.37

    WordPress Ad Inserter plugin <= 2.7.37 - Reflected Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-57693login required≤ 2.8.11

    WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2025-11745contributor+≤ 2.8.7

    Ad Inserter <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field

    Medium 6.4
  • CVE-2026-89427unauthenticated · needs a click≤ 2.8.18

    Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter

    Medium 6.1
  • CVE-2026-19902unauthenticated · needs a click≤ 2.8.18

    Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)

    Medium 6.1
  • CVE-2026-9280unauthenticated · needs a click≤ 2.8.15

    Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode

    Medium 6.1
  • CVE-2026-11984unauthenticated≤ 2.8.16

    Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter

    Medium 5.3
  • CVE-2023-4645unauthenticated≤ 2.7.30

    Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai_ajax

    Medium 5.3
  • CVE-2025-22623unauthenticated · needs a click

    Ad Inserter - Reflected cross-site scripting (XSS)

    Medium 5.1
  • CVE-2026-11900contributor+≤ 2.8.16

    Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory