Impact
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to stored cross‑site scripting caused by insufficient input sanitization and output escaping of user‑supplied attributes in the 'adinserter' shortcode. Attackers with contributor‑level or higher access can inject arbitrary JavaScript into pages. When a visitor accesses a page that includes the malicious shortcode, the injected scripts execute with the visitor’s browser context, potentially compromising user data or performing unauthorized actions.
Affected Systems
The vulnerability affects the WordPress plugin Ad Inserter – Ad Manager & AdSense Ads, versions up to and including 2.8.7.
Risk and Exploitability
The CVSS base score is 6.4, indicating a moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. Because the flaw requires authenticated access at the contributor level or higher, the attack vector is internal user privileges; once exploited, the stored XSS can impact any visitor to the affected page. Administrators should consider the potential for phishing or credential theft against site users and address the flaw promptly.
OpenCVE Enrichment