2026-09-27 6:0CVE-2026-81655WPScan
PUBLISHED5.2

Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

Problem type

  • CWE-94 Improper Control of Generation of Code ('Code Injection')
  • CWE-79 Cross-Site Scripting (XSS)

Affected products

Unknown

Ad Inserter

< 2.8.19 - AFFECTED

References

GitHub Security Advisories

GHSA-8f3r-fqj2-gfj6

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its...

https://github.com/advisories/GHSA-8f3r-fqj2-gfj6

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-81655
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-81655",
    "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
    "assignerShortName": "WPScan",
    "dateUpdated": "2026-09-27T06:00:19.197Z",
    "dateReserved": "2026-08-27T09:36:09.333Z",
    "datePublished": "2026-09-27T06:00:19.197Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "shortName": "WPScan",
        "dateUpdated": "2026-09-27T06:00:19.197Z"
      },
      "title": "Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Ad Inserter  WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors."
        }
      ],
      "affected": [
        {
          "vendor": "Unknown",
          "product": "Ad Inserter",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "2.8.12",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.8.19"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-94 Improper Control of Generation of Code ('Code Injection')",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-79 Cross-Site Scripting (XSS)",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b189ce9a-a930-41e6-bdd1-fdcc3bfb66be/",
          "tags": [
            "exploit",
            "vdb-entry",
            "technical-description"
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Jakub Herman",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "WPScan",
          "type": "coordinator"
        }
      ]
    }
  }
}