Reflected Cross-Site Scripting in Ad Inserter Plugin for WordPress
CVE-2026-9280

6.1MEDIUM

What is CVE-2026-9280?

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization of user inputs and failure to properly escape outputs. This vulnerability exists in all versions up to and including 2.8.15. Attackers can exploit this weakness by tricking users into clicking malicious links, allowing them to inject arbitrary scripts on the site. The exploitation is contingent on enabling iframe mode for at least one advertisement block, a feature often used for displaying AdSense and JavaScript-based ads.

Affected Version(s)

Ad Inserter – Ad Manager & AdSense Ads 0 <= 2.8.15

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

darkestmode
.