PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19902 spacetime CVE debrief

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor by luring them to an attacker-controlled page that frames or links to any ordinary post.

Vendor
spacetime
Product
Ad Inserter – Ad Manager & AdSense Ads
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-01
Original CVE updated
2026-10-03
Advisory published
2026-10-01
Advisory updated
2026-10-03

Who should care

WordPress administrators, security teams, and users of the Ad Inserter plugin should be aware of this vulnerability and take steps to mitigate it. This vulnerability can allow attackers to execute arbitrary JavaScript in the context of the site, potentially leading to unauthorized actions or data theft.

Why it matters

This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site, potentially leading to unauthorized actions or data theft. WordPress administrators and security teams should assess exposure and prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability.

  • Execution of arbitrary JavaScript in the context of the site
  • Potential for unauthorized actions or data theft
  • Possible disruption of site functionality or user experience

Technical summary

The Ad Inserter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18. The plugin does not properly sanitize and escape the '{search-query}' dynamic tag, allowing unauthenticated attackers to execute arbitrary JavaScript in the context of the site. This occurs because the plugin reads the Referer header and tests it with a regex, then substitutes the resulting query value into the ad block without escaping. WordPress administrators and security teams should assess exposure and prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability, especially if ad blocks use the '{search-query}' dynamic tag with

Defensive priority

Defenders should prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability. WordPress administrators and security teams should assess exposure and verify the presence of ad blocks using the '{search-query}' dynamic tag with automatic insertion enabled.

Recommended defensive actions

  • Update the Ad Inserter plugin to a version that fixes this vulnerability
  • Assess exposure and verify the presence of ad blocks using the '{search-query}' dynamic tag with automatic insertion enabled
  • Implement additional security measures to detect and prevent exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability exists due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag in the Ad Inserter plugin. The plugin reads the Referer header and tests it with a regex, then substitutes the resulting query value into the ad block without escaping.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19902 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19902

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19902 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19902

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.