rootpwn

medium · CVSS v3 6.1

CVE-2026-89427

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to reflected cross‑site scripting via the 's' search parameter

Overview

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to reflected cross‑site scripting via the 's' search parameter. Unauthenticated attackers can inject arbitrary scripts into pages that execute when a user follows a crafted link. The flaw exists in all versions up to 2.8.18 and requires a search‑enabled block using {title} or {short-title}.

Description

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature.

Impact

Confidentiality: attackers can steal session cookies or other sensitive data from users. Integrity: malicious scripts can modify page content or redirect users. Availability: repeated exploitation may degrade site performance or cause defacement. Site administrators and visitors are directly impacted.

Remediation

Update the Ad Inserter plugin to version 2.8.19 or later. If an update is not immediately possible, disable the use of {title} or {short-title} placeholders on search pages or remove the block from search results. Ensure the WordPress core and all plugins are kept current and review search page configurations for unnecessary placeholders.

Risk context

The vulnerability has a medium severity rating (CVSS 6.1) and no EPSS data is available. While it does not allow remote code execution, it can lead to data theft or site defacement if users are tricked into clicking malicious links. Defenders should patch promptly to mitigate potential exploitation.

Affected products

  • WordPress Ad Inserter plugin

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
—
EPSS
—

XSS WordPress AdInserter Reflected Medium WebSecurity Plugin

← All CVEs