Review
Advanced Ads
CVE published 2026-07-27
CVE-2026-10082
The Advanced Ads WordPress plugin before version 2.0.23 has a vulnerability that allows users with the Contributor role and above to inject arbitrary web scripts via a shortcode parameter. This occurs because the plugin does not properly sanitize and escape the parameter before outputting it on the page. Such scripts can execute when the affected content is viewed, including by users with higher privilege [truncated]