Impact
The vulnerability is an unauthenticated cross‑site scripting flaw that is present in all WordPress Ad Inserter plugin versions up to 2.8.18. An attacker can inject malicious JavaScript through the plugin’s ad–insertion interface, which then executes in the browsers of site visitors. Exposure includes cookie theft, session hijacking, defacement, phishing, or the execution of arbitrary client‑side code. The impact is on any user who views the affected site content, leading to potential confidentiality and integrity compromise.
Affected Systems
The affected software is the WordPress Ad Inserter plugin from Spacetime, version 2.8.18 or lower. No additional version or product qualifiers are provided.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. The EPSS score is currently unavailable, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is web‑based, requiring no user authentication; an attacker can exploit the flaw by submitting malicious input via the plugin’s administration or front‑end interfaces, causing the script to run within the site’s context.
OpenCVE Enrichment