Executive brief
The Ad Inserter plugin for WordPress, which manages advertising displays like Google AdSense, contains a security flaw that allows attackers to run malicious scripts in a user's browser. This occurs when a user is tricked into clicking a specially crafted link while the plugin is configured to use 'iframe mode' for ads. An exploit could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Ad Inserter plugin for WordPress due to improper sanitization of URL parameters when the plugin is operating in iframe mode (AI_OPTION_IFRAME). Unauthenticated attackers can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. This vulnerability requires the non-default but supported iframe configuration to be enabled on at least one active ad block. The issue affects all versions up to 2.8.15; users should update to a patched version if available.
Affected products
- Igor Funa Ad Inserter – Ad Manager & AdSense Ads Up to and including 2.8.15
Timeline
- 2026-06-06: disclosed
- 2026-06-06: advisory
References
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.11/class.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.11/class.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.11/class.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.15/class.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.15/class.php
- https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.15/class.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3552607%40ad-inserter&new=3552607%40ad-inserter&sfp_email=&sfph_mail=