Reflected Cross-Site Scripting Vulnerability in Ad Inserter Plugin for WordPress
CVE-2026-89427
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-89427?
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS) attacks. This occurs through the 's' search parameter due to inadequate input sanitization and output escaping. If a site administrator has configured an Ad Inserter block that employs the {title} or {short-title} placeholders, which are often employed in search pages—a common feature—it opens a pathway for malicious scripts to be injected. Attackers can capitalize on this vulnerability by tricking users into clicking on crafted links that activate the injected scripts, leading to potential exploitation of user sessions or data theft.
Affected Version(s)
Ad Inserter – Ad Manager & AdSense Ads 0 <= 2.8.18