Junglewise Threat Intelligence

CVE-2026-9280: Igor Funa Ad Inserter reflected XSS in iframe mode

CVE-2026-9280 · Severity: medium · CVSS 6.1 · Published 2026-06-06

Technologies: Igor Funa Ad Inserter. Vendors: Igor Funa.

Executive brief

The Ad Inserter plugin for WordPress, which manages advertising displays like Google AdSense, contains a security flaw that allows attackers to run malicious scripts in a user's browser. This occurs when a user is tricked into clicking a specially crafted link while the plugin is configured to use 'iframe mode' for ads. An exploit could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Ad Inserter plugin for WordPress due to improper sanitization of URL parameters when the plugin is operating in iframe mode (AI_OPTION_IFRAME). Unauthenticated attackers can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. This vulnerability requires the non-default but supported iframe configuration to be enabled on at least one active ad block. The issue affects all versions up to 2.8.15; users should update to a patched version if available.

Affected products

  • Igor Funa Ad Inserter – Ad Manager & AdSense Ads Up to and including 2.8.15

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References

Related threats