Sceawere
Vulnerability Detail
CVE-2026-81655UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ad Inserter Improper Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- Ad Inserter
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-27T06:16:58.003Z",
"pubdate": "2026-09-27T06:16:58.003Z",
"executiveSummary": "The Ad Inserter WordPress plugin, in versions prior to 2.8.19, contains a critical security vulnerability involving improper access control and insufficient input validation. This flaw allows authenticated users, including those with minimal privileges such as the 'subscriber' role, to access restricted settings pages if specific configurations are enabled within the plugin.\nThe vulnerability stems from a lack of adequate capability checks on administrative settings pages, compounded by the absence of server-side filtering for user-supplied data. Consequently, attackers can inject arbitrary PHP code or malicious scripts into the plugin's configuration settings.\nSuccessful exploitation results in arbitrary code execution on the server or persistent Cross-Site Scripting (XSS), potentially leading to complete site compromise, unauthorized data access, or the deployment of malware to visitors. The risk is considered high due to the low barrier for exploitation, requiring only a standard subscriber account on a vulnerable WordPress installation.",
"technicalDetails": "The vulnerability resides within the access control logic and the input handling mechanism of the Ad Inserter plugin. The root cause is twofold: first, the plugin fails to perform rigorous capability checks (e.g., current_user_can('manage_options')) on specific administrative endpoints, allowing unauthorized users to reach sensitive configuration interfaces if the plugin's internal settings permit broad access.\nSecond, the plugin lacks server-side sanitization and validation for the data saved within these settings. This facilitates an Insecure Direct Object Reference (IDOR) style configuration exposure where an attacker can interact with data fields intended only for administrative use.\nThe attack flow begins with an authenticated user (subscriber) navigating to the improperly protected settings page. By leveraging the lack of input filtering, the attacker injects malicious payloads—such as PHP code blocks or JavaScript—into fields that the plugin subsequently processes. Because the plugin may evaluate this stored code or serve it directly to visitors without escaping, the payload executes within the context of the WordPress environment.\nIn the case of PHP injection, the payload is executed by the server-side interpreter, granting the attacker the ability to interact with the database, execute shell commands, or modify core WordPress files. In the case of stored XSS, the payload is injected into the rendered HTML output on the site, executing within the browsers of visitors or administrators who view the affected page. This persistent injection allows for session hijacking, administrative action spoofing, and redirection of site traffic.\nThe vulnerability affects all versions of Ad Inserter prior to 2.8.19. Exploitation is limited to environments where the plugin is configured to permit access beyond the default administrative roles. As the plugin does not adequately restrict these administrative interfaces to privileged users, it creates an escalation path from a subscriber role to full administrative or system-level control over the WordPress instance. No external network exposure beyond legitimate plugin access is required, as the vector is internal to the application's authenticated session management."
}