Executive Summary
A broken access control vulnerability (CVE-2026-81655) has been disclosed in Ad Inserter (Ad Manager & AdSense Ads), a WordPress plugin with 300,000+ active installations. One of the plugin's settings pages does not correctly restrict access by capability, making it reachable by any logged-in user — including accounts as low-privileged as subscriber, depending on the site's own configuration. Because the plugin also fails to filter the content saved through that page, a low-privilege user who reaches it can store code that later executes as PHP or gets served unescaped to site visitors.
CVSS Score: 7.5 (High, CVSS 3.1)
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-81655 |
| CVSS Score | 7.5 (High), CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Type | Code Injection (CWE-94), with contributing Improper Access Control (CWE-284) and XSS (CWE-79) |
| Privileges Required | Low — a standard logged-in account (subscriber or above, depending on site configuration) |
| Attack Vector | Network |
| User Interaction | None |
| Public Exploit | Not observed as of publication |
| Assigner | WPScan (CVE reserved 2026-08-27) |
| Published | 2026-09-27 |
Affected Products
| Plugin | Affected Versions | Fixed Version | Install Base |
|---|---|---|---|
| Ad Inserter (Ad Manager & AdSense Ads) | 2.8.12 through 2.8.19, before 2.8.19 | 2.8.19 | 300,000+ active installs |
Technical Details
Root Cause
Ad Inserter ships a settings page that is intended for administrator use but is not properly gated behind an administrator-level capability check. On sites where the plugin's own configuration allows lower-privileged roles to reach this area, any logged-in user — down to subscriber — can load the page. Compounding the exposure, the plugin does not sanitize or filter the content submitted through that page before storing and later rendering it, so a user who should never see this settings screen can also use it to plant executable code.
Attack Chain
1. Attacker registers or already holds a low-privilege account
(e.g. subscriber) on a WordPress site running a vulnerable
Ad Inserter version with permissive settings-access configuration
2. Attacker navigates directly to the unrestricted Ad Inserter
settings page, bypassing the intended admin-only boundary
3. Attacker submits malicious ad-insertion code through the page;
the plugin stores it without sanitization
4. The stored code executes as PHP (or is served unescaped to
visitors) the next time the affected ad placement rendersImpact Assessment
| Impact Area | Description |
|---|---|
| Privilege Escalation | Low-privilege accounts gain effective control over site-wide ad-injection code |
| Site-Wide Code Execution | Malicious code injected via ad placements can run on every page that renders the affected slot |
| Visitor Exposure | Unfiltered output can also be used to serve malicious scripts to site visitors |
| Scale | 300,000+ active installations widen the exposed population |
Recommendations
Immediate Actions
- Update Ad Inserter to version 2.8.19 or later via the WordPress admin or WP-CLI (
wp plugin update ad-inserter). - Audit user roles and registration settings — disable open self-registration and review which roles are permitted on the site if not required for normal operation.
- Review Ad Inserter's saved ad codes for unexpected or unfamiliar content added by non-administrator accounts.
- Confirm the plugin's access-restriction settings are set to the most restrictive option consistent with site needs.
Detection
- Audit user-role changes and new registrations around the disclosure window.
- Review Ad Inserter configuration history/logs, if available, for edits made by non-administrator accounts.