Impact
A reflected cross‑site scripting flaw exists in the WordPress Ad Inserter Pro plugin that allows an attacker to inject malicious script content into a web page. When user input is incorporated into the plugin’s output without proper encoding or filtering, an attacker can cause a victim’s browser to execute arbitrary code. This can lead to theft of credentials, session hijacking, or the delivery of additional malware, compromising the confidentiality and integrity of site visitors and administrators.
Affected Systems
WordPress sites running the Ad Inserter Pro plugin, versions up through 2.7.39. The issue is fixed in version 2.8.0 and later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, and the EPSS score of less than 1% means the likelihood of exploitation is currently low, though not impossible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a reflected XSS injection via the plugin’s processing of user or query string data, which an attacker can trigger by crafting a specially formed URL or form submission.
OpenCVE Enrichment
EUVD