Junglewise Threat Intelligence

CVE-2026-57693: Spacetime Ad Inserter XSS due to improper access control

CVE-2026-57693 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Spacetime Ad Inserter.

Executive brief

Spacetime Ad Inserter, a popular WordPress plugin used to manage and display advertisements, contains a security flaw that could allow unauthorized script execution. An attacker with basic user privileges could trick a site administrator into performing an action that triggers a malicious script. If successful, this could lead to unauthorized website redirects, the display of fraudulent advertisements, or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Spacetime Ad Inserter plugin for WordPress (versions up to and including 2.8.11). The flaw stems from improper neutralization of input during web page generation combined with incorrectly configured access control security levels. An attacker with 'Subscriber' level privileges can exploit this by injecting malicious scripts that are executed in the context of a more privileged user's session, provided there is some form of user interaction (e.g., clicking a link). This is classified as a stored or reflected XSS depending on the specific injection point within the plugin's ad management interface. The issue is resolved in version 2.8.12.

Affected products

  • Spacetime Ad Inserter <= 2.8.11

Timeline

  • 2026-02-08: disclosed: Reported by timomangcut
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE-2026-57693
  • 2026-07-13: patched: Version 2.8.12 released to address the vulnerability

References