Impact
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress contains an authorization bypass flaw in the ai_ajax function. A missing capability check allows any unauthenticated user to request and retrieve the contents of ad blocks that an administrator has marked for administrator‑only visibility, leading to the disclosure of potentially sensitive advertising data and providing competitors with insight into ad strategies. This weakness is identified as CWE‑862.
Affected Systems
All installations of Ad Inserter up to and including version 2.8.16 running on WordPress sites are vulnerable. The issue is confined to the plugin’s AJAX interface and does not affect other WordPress components directly.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The available data does not show an EPSS value, and the vulnerability is not listed in the CISA KEV catalog, suggesting no current exploitation reports. A remote attacker can exercise the vulnerability by sending unauthenticated HTTP requests to the ai_ajax endpoint. No special privileges or exploits are required beyond the simple crafted request.
OpenCVE Enrichment