Description
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.
Published: 2026-10-01
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in the Ad Inserter WordPress plugin, where unsanitized input from the HTTP Referer header is embedded into the output of the '{search-query}' dynamic tag. An attacker can supply a malicious referer that includes JavaScript, which the plugin percent‑decodes and inserts into the page without escaping. This allows the attacker to execute arbitrary JavaScript in the context of any visitor, including administrators, when they load a page that contains the vulnerable tag. The weakness is an input validation issue identified as CWE‑79.

Affected Systems

The affected product is the Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress, versions up to and including 2.8.18. Sites running these versions with ad blocks that use the '{search-query}' tag and automatic insertion enabled are vulnerable. Upgrading to any later release removes the flaw, so systems using 2.8.18 or earlier need to be updated.

Risk and Exploitability

The CVSS base score is 6.1, indicating a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is possible without authentication and can be performed by directing authenticated or unauthenticated visitors to a crafted page that sets a Referer header matching the regular expression used by the plugin, thereby triggering the reflected XSS. Because the attack requires only the presence of the vulnerable tag in an ad block, the risk is effectively for any site using the default settings of the plugin.

Generated by OpenCVE AI on October 1, 2026 at 09:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ad Inserter to version 2.8.19 or later to eliminate the unescaped referer handling.
  • Disable or remove the '{search-query}' tag from ad blocks if upgrading immediately is not possible, so no unsanitized data is inserted.
  • Configure the web server or application to validate and sanitize the HTTP Referer header before it reaches the plugin, or block requests with suspect referer patterns.

Generated by OpenCVE AI on October 1, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\.\/](google|yahoo|bing|ask)\.[a-z\.]{2,5}[\/]/i. The leading [\.\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.
Title Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T07:40:23.197Z

Reserved: 2026-08-14T19:15:32.388Z

Link: CVE-2026-19902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T08:16:51.580

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-19902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T09:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')