Reflected Cross-Site Scripting Vulnerability in Ad Inserter Plugin for WordPress
CVE-2026-89427

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-89427?

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS) attacks. This occurs through the 's' search parameter due to inadequate input sanitization and output escaping. If a site administrator has configured an Ad Inserter block that employs the {title} or {short-title} placeholders, which are often employed in search pages—a common feature—it opens a pathway for malicious scripts to be injected. Attackers can capitalize on this vulnerability by tricking users into clicking on crafted links that activate the injected scripts, leading to potential exploitation of user sessions or data theft.

Affected Version(s)

Ad Inserter – Ad Manager & AdSense Ads 0 <= 2.8.18

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.