ad_inserter_project CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

ad_inserter_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ad_inserter_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk csrf, vendor risk path handling, and vendor risk input validation; exposure may include vendor impact unexpected behavior in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-4668 The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths. [email protected] 5.3 0.51% 2023-10-20 2026-06-17
CVE-2023-1549 The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present [email protected] 7.2 16.90% 2023-05-15 2026-06-17
CVE-2022-0901 The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters [email protected] 6.1 3.63% 2022-04-04 2026-06-17
CVE-2022-0288 The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting [email protected] 6.1 2.39% 2022-02-21 2026-06-17
CVE-2015-9497 The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. [email protected] 8.8 0.98% 2019-10-22 2026-06-16
CVE-2019-15324 The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. [email protected] 8.8 3.64% 2019-08-22 2026-06-16
CVE-2019-15323 The ad-inserter plugin before 2.4.20 for WordPress has path traversal. [email protected] 7.5 2.03% 2019-08-22 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence