Reflected Cross-Site Scripting in Ad Inserter Plugin for WordPress
CVE-2026-9280
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 June 2026
What is CVE-2026-9280?
The Ad Inserter β Ad Manager & AdSense Ads plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs and failure to properly escape outputs. This vulnerability exists in all versions up to and including 2.8.15. Attackers can exploit this weakness by tricking users into clicking malicious links, allowing them to inject arbitrary scripts on the site. The exploitation is contingent on enabling iframe mode for at least one advertisement block, a feature often used for displaying AdSense and JavaScript-based ads.
Affected Version(s)
Ad Inserter β Ad Manager & AdSense Ads 0 <= 2.8.15