Cross-Site Scripting Vulnerability in Ad Inserter by Spacetime
CVE-2026-57693

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57693?

A Cross-Site Scripting vulnerability in the Ad Inserter plugin by Spacetime allows adversaries to inject malicious scripts into web pages, potentially leading to unauthorized account access and data theft. This vulnerability arises due to improper input handling in the plugin, affecting all versions up to 2.8.11. Administrators are urged to review their access control settings and ensure that appropriate security measures are in place to mitigate exploitation risks.

Affected Version(s)

Ad Inserter 0 <= 2.8.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.