๐Ÿ” CVE Alert

CVE-2026-81655

UNKNOWN 0.0

Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

Vendor unknown
Product ad inserter
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ad inserter

Be the first to know when new unknown vulnerabilities affecting unknown ad inserter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Ad Inserter
2.8.12 < 2.8.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b189ce9a-a930-41e6-bdd1-fdcc3bfb66be/

Credits

Jakub Herman WPScan