PatchSiren cyber security CVE debrief
CVE-2026-19902 spacetime CVE debrief
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor by luring them to an attacker-controlled page that frames or links to any ordinary post.
- Vendor
- spacetime
- Product
- Ad Inserter – Ad Manager & AdSense Ads
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators, security teams, and users of the Ad Inserter plugin should be aware of this vulnerability and take steps to mitigate it. This vulnerability can allow attackers to execute arbitrary JavaScript in the context of the site, potentially leading to unauthorized actions or data theft.
Why it matters
This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site, potentially leading to unauthorized actions or data theft. WordPress administrators and security teams should assess exposure and prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability.
- Execution of arbitrary JavaScript in the context of the site
- Potential for unauthorized actions or data theft
- Possible disruption of site functionality or user experience
Technical summary
The Ad Inserter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18. The plugin does not properly sanitize and escape the '{search-query}' dynamic tag, allowing unauthenticated attackers to execute arbitrary JavaScript in the context of the site. This occurs because the plugin reads the Referer header and tests it with a regex, then substitutes the resulting query value into the ad block without escaping. WordPress administrators and security teams should assess exposure and prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability, especially if ad blocks use the '{search-query}' dynamic tag with
Defensive priority
Defenders should prioritize updating the Ad Inserter plugin to a version that fixes this vulnerability. WordPress administrators and security teams should assess exposure and verify the presence of ad blocks using the '{search-query}' dynamic tag with automatic insertion enabled.
Recommended defensive actions
- Update the Ad Inserter plugin to a version that fixes this vulnerability
- Assess exposure and verify the presence of ad blocks using the '{search-query}' dynamic tag with automatic insertion enabled
- Implement additional security measures to detect and prevent exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability exists due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag in the Ad Inserter plugin. The plugin reads the Referer header and tests it with a regex, then substitutes the resulting query value into the ad block without escaping.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19902 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19902
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19902 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19902
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/class.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3709957/ad-inserter/trunk/ad-inserter.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.