medium · CVSS v3 6.1
CVE-2026-89427
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to reflected cross‑site scripting via the 's' search parameter
Overview
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to reflected cross‑site scripting via the 's' search parameter. Unauthenticated attackers can inject arbitrary scripts into pages that execute when a user follows a crafted link. The flaw exists in all versions up to 2.8.18 and requires a search‑enabled block using {title} or {short-title}.
Description
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature.
Impact
Confidentiality: attackers can steal session cookies or other sensitive data from users. Integrity: malicious scripts can modify page content or redirect users. Availability: repeated exploitation may degrade site performance or cause defacement. Site administrators and visitors are directly impacted.
Remediation
Update the Ad Inserter plugin to version 2.8.19 or later. If an update is not immediately possible, disable the use of {title} or {short-title} placeholders on search pages or remove the block from search results. Ensure the WordPress core and all plugins are kept current and review search page configurations for unnecessary placeholders.
Risk context
The vulnerability has a medium severity rating (CVSS 6.1) and no EPSS data is available. While it does not allow remote code execution, it can lead to data theft or site defacement if users are tricked into clicking malicious links. Defenders should patch promptly to mitigate potential exploitation.
Affected products
- WordPress Ad Inserter plugin
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- —
- EPSS
- —