🔐 CVE Alert

CVE-2026-10082

UNKNOWN 0.0

Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users.

Vendor unknown
Product advanced ads
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown advanced ads

Be the first to know when new unknown vulnerabilities affecting unknown advanced ads are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Advanced Ads
0 < 2.0.23

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/088a832d-2153-432e-849f-2c22b63a1b54/

Credits

Pablo González and Francisco José Ramírez WPScan