Authorization Bypass Vulnerability in Ad Inserter Plugin for WordPress
CVE-2026-11983
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-11983?
The Ad Inserter β Ad Manager & AdSense Ads plugin for WordPress is susceptible to an authorization bypass issue due to a lack of necessary capability checks within the ai_ajax function. This vulnerability allows unauthenticated users to access and view ad block contents that are intended to be restricted solely to administrators. As a result, sensitive information can be exposed, potentially leading to unauthorized manipulation or display of ads on the website. Users are advised to update their plugins to the latest version to mitigate this risk.
Affected Version(s)
Ad Inserter β Ad Manager & AdSense Ads 0 <= 2.8.16