CVE-2026-57693 is a Cross-site Scripting vulnerability in Ad Inserter, a WordPress plugin. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. The issue affects Ad Inserter from n/a through <= 2.8.11. The vulnerability is caused by Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/ [truncated]
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference, allowing authenticated attackers with Contributor-level access and above to read the full content of arbitrary posts, including Private, Draft, Pending, Trashed, and password-protected posts owned by other users. This is due to insufficient authorization checks in the replace_ai_tags() functi [truncated]