rootpwn

medium · CVSS v3 6.1

CVE-2026-19902

The Ad Inserter plugin for WordPress is vulnerable to reflected XSS via the Referer header when using the {search-query} tag. Attackers can

Overview

The Ad Inserter plugin for WordPress is vulnerable to reflected XSS via the Referer header when using the {search-query} tag. Attackers can inject arbitrary JavaScript into any visitor's browser, including admins, by tricking them to visit a malicious page. This flaw exists in all versions up to 2.8.18.

Description

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.

Impact

Confidentiality: attackers can read or modify page content; Integrity: arbitrary script can alter page behavior; Availability: not directly impacted. Administrators and regular visitors are affected as any user who loads a page with the vulnerable tag can be compromised.

Remediation

Upgrade the Ad Inserter plugin to version 2.8.19 or later. If an upgrade is not possible, disable the {search-query} tag or remove ad blocks that use it, and configure the plugin to disable automatic insertion. Apply a Content Security Policy that blocks inline scripts and enforce HTTPS. Keep WordPress core and other plugins up to date.

Risk context

The vulnerability has a CVSS v3 score of 6.1 and is classified as medium severity. No EPSS data is available. Defenders should treat it as a moderate risk that could be exploited by unauthenticated attackers.

Affected products

  • Ad Inserter 2.8.18
  • Ad Inserter 2.8.17
  • Ad Inserter 2.8.16
  • Ad Inserter 2.8.15
  • Ad Inserter 2.8.14
  • Ad Inserter 2.8.13
  • Ad Inserter 2.8.12
  • Ad Inserter 2.8.11

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
—
EPSS
—

XSS WordPress Ad Inserter Reflected XSS Referer Medium CVE-2026-19902

← All CVEs