Impact
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress allows an unauthenticated attacker to retrieve administrator‑configured header and footer code blocks that have been disabled from public display. This is caused by a missing capability check on the ai‑debug‑code URL parameter, creating an authorization bypass. The attacker can view potentially sensitive code that may include credentials, tracking scripts, or other proprietary logic, thereby impacting the confidentiality of the site’s configuration.
Affected Systems
Spacetime’s Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is affected. All releases up to and including version 2.8.16 are vulnerable; newer releases are not listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score indicates that exploitation is unlikely but not impossible. The vulnerability is listed as not included in the CISA KEV catalog. An attacker who crafts a request containing the ai‑debug‑code parameter can retrieve the code blocks without any authentication or privilege escalation, suggesting that the attack vector is purely remote and unauthenticated. The risk to users is primarily the disclosure of site configuration, which could aid further attacks such as phishing or script injection.
OpenCVE Enrichment