Authorization Bypass in Ad Inserter Plugin for WordPress
CVE-2026-11984

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 September 2026

What is CVE-2026-11984?

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is susceptible to an authorization bypass flaw. This vulnerability arises from a lack of capability checks on the 'ai-debug-code' URL parameter, exposing administrator settings for header and footer code blocks. An unauthenticated attacker can exploit this weakness to view sensitive configuration details that were intended to be restricted from public access, potentially leading to further exploitation or data leakage.

Affected Version(s)

Ad Inserter – Ad Manager & AdSense Ads 0 <= 2.8.16

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Evan
.