Impact
The vulnerability exists in the Ad Inserter WordPress plugin in versions 2.8.12 through 2.8.18. It fails to enforce proper access control on a settings page, allowing any logged‑in user—including those with the Subscriber role—to store arbitrary PHP code. Because the plugin does not filter this input, the code is executed on the server, giving an attacker full control over the web application, and when rendered without escaping it also enables stored Cross‑Site Scripting for site visitors.
Affected Systems
Sites running the Ad Inserter WordPress plugin, specifically versions 2.8.12 to 2.8.18, are affected.
Risk and Exploitability
The CVSS score is not disclosed and the EPSS score is unavailable, but the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authentication with a Subscriber role. Once a subscriber uploads malicious code, it runs with the web server’s privileges, leading to a complete site compromise, while the stored XSS component can be used for phishing or credential theft against site visitors.
OpenCVE Enrichment