SECURITYHIGHCVE-2026-81655

Ad Inserter Plugin Broken Access Control Enables Code Injection (CVE-2026-81655)

Ad Inserter for WordPress lets logged-in users as low as subscriber reach an unrestricted settings page and inject unfiltered code.

Dylan H.

Security Team

September 27, 2026
4 min read
Ad Inserter Plugin Broken Access Control Enables Code Injection (CVE-2026-81655)

Affected Products

  • Ad Inserter (Ad Manager & AdSense Ads) 2.8.12 through 2.8.19, before 2.8.19

Executive Summary

A broken access control vulnerability (CVE-2026-81655) has been disclosed in Ad Inserter (Ad Manager & AdSense Ads), a WordPress plugin with 300,000+ active installations. One of the plugin's settings pages does not correctly restrict access by capability, making it reachable by any logged-in user — including accounts as low-privileged as subscriber, depending on the site's own configuration. Because the plugin also fails to filter the content saved through that page, a low-privilege user who reaches it can store code that later executes as PHP or gets served unescaped to site visitors.

CVSS Score: 7.5 (High, CVSS 3.1)


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-81655
CVSS Score7.5 (High), CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
TypeCode Injection (CWE-94), with contributing Improper Access Control (CWE-284) and XSS (CWE-79)
Privileges RequiredLow — a standard logged-in account (subscriber or above, depending on site configuration)
Attack VectorNetwork
User InteractionNone
Public ExploitNot observed as of publication
AssignerWPScan (CVE reserved 2026-08-27)
Published2026-09-27

Affected Products

PluginAffected VersionsFixed VersionInstall Base
Ad Inserter (Ad Manager & AdSense Ads)2.8.12 through 2.8.19, before 2.8.192.8.19300,000+ active installs

Technical Details

Root Cause

Ad Inserter ships a settings page that is intended for administrator use but is not properly gated behind an administrator-level capability check. On sites where the plugin's own configuration allows lower-privileged roles to reach this area, any logged-in user — down to subscriber — can load the page. Compounding the exposure, the plugin does not sanitize or filter the content submitted through that page before storing and later rendering it, so a user who should never see this settings screen can also use it to plant executable code.

Attack Chain

1. Attacker registers or already holds a low-privilege account
   (e.g. subscriber) on a WordPress site running a vulnerable
   Ad Inserter version with permissive settings-access configuration
 
2. Attacker navigates directly to the unrestricted Ad Inserter
   settings page, bypassing the intended admin-only boundary
 
3. Attacker submits malicious ad-insertion code through the page;
   the plugin stores it without sanitization
 
4. The stored code executes as PHP (or is served unescaped to
   visitors) the next time the affected ad placement renders

Impact Assessment

Impact AreaDescription
Privilege EscalationLow-privilege accounts gain effective control over site-wide ad-injection code
Site-Wide Code ExecutionMalicious code injected via ad placements can run on every page that renders the affected slot
Visitor ExposureUnfiltered output can also be used to serve malicious scripts to site visitors
Scale300,000+ active installations widen the exposed population

Recommendations

Immediate Actions

  1. Update Ad Inserter to version 2.8.19 or later via the WordPress admin or WP-CLI (wp plugin update ad-inserter).
  2. Audit user roles and registration settings — disable open self-registration and review which roles are permitted on the site if not required for normal operation.
  3. Review Ad Inserter's saved ad codes for unexpected or unfamiliar content added by non-administrator accounts.
  4. Confirm the plugin's access-restriction settings are set to the most restrictive option consistent with site needs.

Detection

  • Audit user-role changes and new registrations around the disclosure window.
  • Review Ad Inserter configuration history/logs, if available, for edits made by non-administrator accounts.

References