PT-2026-55514 · Spacetime · Ad Inserter - Ad Manager/Adsense Ads
Nightward
·
Published
2026-07-03
·
Updated
2026-07-03
·
CVE-2026-11900
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace ai tags() function processing a {reusable-block-N} tag pattern that calls get post field('post content', N) without verifying the requesting user's capability with current user can('read post'), without restricting the post type to 'wp block', and without checking the post status. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the full content of arbitrary posts including Private, Draft, Pending, Trashed, and password-protected posts owned by other users, by placing the shortcode in a post they own and previewing it.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ad Inserter - Ad Manager/Adsense Ads