CVE-2026-97077: WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ad Inserter pluginto a version that resolves this vulnerability.Fixed in 2.8.19
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is described as unauthenticated, so the attacker does not need a WordPress account or prior privileges. Successful exploitation requires user interaction, as indicated by the UI:R vector.
Which installations should be considered affected?
Ad Inserter versions 2.8.18 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration or WordPress setup is required.
What is the likely impact if exploitation succeeds?
The CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. The issue is an XSS vulnerability, so malicious script could execute in the context of a user who interacts with the exploit.