Impact
The vulnerability is a reflected cross‑site scripting flaw in the Ad Inserter WordPress plugin, where unsanitized input from the HTTP Referer header is embedded into the output of the '{search-query}' dynamic tag. An attacker can supply a malicious referer that includes JavaScript, which the plugin percent‑decodes and inserts into the page without escaping. This allows the attacker to execute arbitrary JavaScript in the context of any visitor, including administrators, when they load a page that contains the vulnerable tag. The weakness is an input validation issue identified as CWE‑79.
Affected Systems
The affected product is the Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress, versions up to and including 2.8.18. Sites running these versions with ad blocks that use the '{search-query}' tag and automatic insertion enabled are vulnerable. Upgrading to any later release removes the flaw, so systems using 2.8.18 or earlier need to be updated.
Risk and Exploitability
The CVSS base score is 6.1, indicating a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is possible without authentication and can be performed by directing authenticated or unauthenticated visitors to a crafted page that sets a Referer header matching the regular expression used by the plugin, thereby triggering the reflected XSS. Because the attack requires only the presence of the vulnerable tag in an ad block, the risk is effectively for any site using the default settings of the plugin.
OpenCVE Enrichment