Impact
The Advanced Ads plugin prior to version 2.0.23 does not validate or escape the 'ad_args' parameter in the 'the_ad' shortcode. An attacker who has Contributor-level or higher access can embed malicious JavaScript that is stored with the content and runs in the browsers of any user who views that page, potentially leading to data theft, session hijacking, or defacement.
Affected Systems
The vulnerability affects the Advanced Ads WordPress plugin. Any installation using a version earlier than 2.0.23 is impacted. The issue is triggered when content includes the processed 'the_ad' shortcode with an unsanitized 'ad_args' value.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity. The exploit is feasible for anyone who can edit or insert content using a Contributor or higher role, making it a local web-based attack. The EPSS score of <1% indicates a very low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, yet the presence of stored code that executes in browsers of higher-privileged users makes exploitation likely in environments where elevated roles are present.
OpenCVE Enrichment