Sceawere

Vulnerability Detail

CVE-2026-97077UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ad Inserter Unauthenticated XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Spacetime
Product
Ad Inserter
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:34.470Z",
  "pubdate": "2026-09-30T13:17:34.470Z",
  "executiveSummary": "The Ad Inserter plugin for WordPress, in versions 2.8.18 and below, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the browsers of unsuspecting users, including administrative sessions.\nThe vulnerability stems from improper neutralization of user-supplied input before rendering it in the browser. By leveraging this flaw, an attacker can bypass authentication requirements to execute malicious scripts. The potential impact is significant, encompassing session hijacking, redirection to malicious domains, unauthorized actions performed on behalf of the administrator, and potential full site compromise. Because the vulnerability does not require prior authentication, it poses a substantial risk to any WordPress installation utilizing the affected plugin versions. Organizations are advised to treat this as a high-severity incident and prioritize remediation efforts immediately.",
  "technicalDetails": "The vulnerability is a reflected/stored Cross-Site Scripting (XSS) issue resulting from inadequate input validation and output encoding within the Ad Inserter plugin. Specifically, the plugin fails to sanitize user-controllable input fields or parameters before they are processed and rendered back into the web page context.\nThe root cause lies in the application's failure to implement proper context-aware output encoding (such as esc_html() or esc_js()) when handling parameters that are reflected in the plugin's interface or specific frontend components. When an attacker supplies a crafted payload—typically consisting of HTML tags like <script> or event handlers like onload or onerror—the application inadvertently treats these inputs as executable content rather than plain text.\nThe attack flow proceeds as follows: First, the attacker identifies the specific injection vector, which could be a query parameter or a configuration field that is improperly echoed. Second, the attacker crafts a malicious payload designed to execute in the target user's browser. Third, the attacker tricks an authenticated user, such as an administrator, into visiting a specifically crafted URL or interacting with the malicious input field. Once the page loads, the browser interprets the injected script as legitimate code originating from the trusted domain. This executes the script within the security context of the victim's session.\nBecause the execution happens in the user's browser, the attacker can perform actions such as stealing session cookies, capturing keystrokes, or modifying the site's content in real-time. If the victim is an administrator, the attacker could effectively manipulate the WordPress site by creating new administrative accounts, modifying site settings, or installing malicious plugins. The vulnerability is exploitable over a network without the need for credentials, making it particularly dangerous for public-facing sites that utilize the Ad Inserter plugin for ad management. The lack of proper input filtering during the data entry or rendering phase facilitates this bypass of standard security controls."
}
CVE-2026-97077: Ad Inserter Unauthenticated XSS Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere