PT-2026-55514 · Spacetime · Ad Inserter - Ad Manager/Adsense Ads

Nightward

·

Published

2026-07-03

·

Updated

2026-07-03

·

CVE-2026-11900

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace ai tags() function processing a {reusable-block-N} tag pattern that calls get post field('post content', N) without verifying the requesting user's capability with current user can('read post'), without restricting the post type to 'wp block', and without checking the post status. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the full content of arbitrary posts including Private, Draft, Pending, Trashed, and password-protected posts owned by other users, by placing the shortcode in a post they own and previewing it.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11900

Affected Products

Ad Inserter - Ad Manager/Adsense Ads