CVE-2026-19902: Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)

Published Oct 1, 2026
·
Updated

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replaceaitags() reads $SERVER['HTTPREFERER'] and tests it with the regex /\.\/\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parsestr() and substitutes the resulting 'q' (or 'p') value into the block via pregreplace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.

Affected Software

1 affected component
Ad Inserter Ad Inserter – Ad Manager & AdSense Ads<=2.8.18

Event History

Oct 1, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Only sites running Ad Inserter version 2.8.18 or earlier that have an ad block containing the {search-query} dynamic tag with automatic insertion enabled are exposed. The vulnerable configuration uses a documented plugin feature and does not require the attacker to authenticate.

2

What does an attacker need to do to trigger the issue?

An attacker needs to lure a visitor to an attacker-controlled page that frames or links to an ordinary post on the target site. The attacker-controlled referrer must contain a path segment such as /google.com/ and supply a malicious q or p query value, which is inserted into the ad block without escaping.

3

Who is at risk if the vulnerable ad block is enabled?

Any visitor who follows the attacker’s crafted navigation can have JavaScript executed in the target site’s context. This includes signed-in administrators, making their active site session potentially exposed to the injected script.

4

What can be done if updating is not immediately possible?

Remove the {search-query} dynamic tag from automatically inserted ad-block code, or disable automatic insertion for blocks that use it. This prevents the vulnerable referrer-derived q or p value from being substituted into displayed block content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203