Executive brief
The Ad Inserter plugin for WordPress, which is used to manage and display advertisements, contains a security flaw that allows certain users to view restricted content. Authenticated users with at least Contributor-level access can exploit this to read private, draft, or password-protected posts created by other authors. This could lead to the unauthorized disclosure of sensitive information or unpublished site content.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) located in the replace_ai_tags() function of the Ad Inserter plugin. The function processes a {reusable-block-N} tag pattern by calling get_post_field('post_content', N) without implementing proper authorization checks such as current_user_can('read_post'). Additionally, the plugin fails to restrict the post type to 'wp_block' or verify the post status. An authenticated attacker with Contributor-level permissions can exploit this by placing a crafted shortcode in a post they control and previewing it to retrieve the content of any post ID. A patch was released in version 2.8.17.
Affected products
- spacetime Ad Inserter – Ad Manager & AdSense Ads up to and including 2.8.16
Timeline
- 2026-07-03: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php