Sensitive Information Exposure in Ad Inserter Plugin for WordPress
CVE-2023-4645
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 October 2023
What is CVE-2023-4645?
The Ad Inserter plugin for WordPress has a vulnerability that may lead to sensitive information exposure, affecting versions up to and including 2.7.30. This flaw can be exploited through the ai_ajax function, permitting unauthenticated attackers to access sensitive data such as post titles, slugs of protected posts (including their corresponding passwords), usernames, user roles, and the plugin license key if remote debugging is enabled, which is typically set to disabled by default.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ad Inserter β Ad Manager & AdSense Ads * <= 2.7.30
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved