PT-2026-47138 · WordPress · Ad Inserter
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ad Inserter – Ad Manager & AdSense Ads versions prior to 2.8.16
Description
The plugin is subject to Reflected Cross-Site Scripting (XSS), a flaw where an application includes untrusted data in a web page without proper validation, allowing attackers to execute scripts in the victim's browser. This occurs via URL parameters when iframe mode is active due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts if a user is tricked into clicking a malicious link. This requires the
AI OPTION IFRAME configuration to be enabled on at least one ad block on the targeted page.Recommendations
Update the plugin to a version later than 2.8.15.
As a temporary mitigation, disable the
AI OPTION IFRAME (iframe mode) on all ad blocks.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ad Inserter