CVE-2025-11745: Ad Inserter <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' shortcode in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11745?
CVE-2025-11745 is considered a critical vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-11745?
To fix CVE-2025-11745, update the Ad Inserter – Ad Manager & AdSense Ads plugin to version 2.8.8 or later.
What are the risks associated with CVE-2025-11745?
The risks of CVE-2025-11745 include data theft, session hijacking, and the potential for complete site takeover through executed malicious scripts.
Who is affected by CVE-2025-11745?
Any WordPress site using the Ad Inserter – Ad Manager & AdSense Ads plugin versions up to and including 2.8.7 is affected by CVE-2025-11745.
What type of attacks can CVE-2025-11745 enable?
CVE-2025-11745 can enable Stored Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by other users.