The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an [truncated]
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor by luring them to an attacker-controlled page that frames or links to any ordinary post.
CVE-2026-57693 is a Cross-site Scripting vulnerability in Ad Inserter, a WordPress plugin. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. The issue affects Ad Inserter from n/a through <= 2.8.11. The vulnerability is caused by Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/ [truncated]
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference, allowing authenticated attackers with Contributor-level access and above to read the full content of arbitrary posts, including Private, Draft, Pending, Trashed, and password-protected posts owned by other users. This is due to insufficient authorization checks in the replace_ai_tags() functi [truncated]