Ad Inserter is a WordPress plugin that, despite a narrow product scope, achieves broad deployment across web publishers and content sites, and its vulnerability footprint reflects the challenges of a widely embedded web-facing component. The recurring exposure centers on input-handling and authorization weaknesses—including cross-site scripting, cross-site request forgery, path traversal, and missing authorization checks—that are endemic to server-side WordPress extensions, and these vulnerabilities have an elevated tendency toward public exploit availability. Defenders should prioritize patching this plugin on internet-exposed WordPress instances and monitor updates closely, as live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ad Inserter Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1549HIGH The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injecti | May 15, 2023 | 7.2 | 31 | NO | NO |
CVE-2019-15324HIGH The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. | Aug 22, 2019 | 8.8 | 26 | NO | NO |
CVE-2022-0288MEDIUM The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it | Feb 21, 2022 | 6.1 | 25 | NO | YES |
CVE-2019-15323HIGH The ad-inserter plugin before 2.4.20 for WordPress has path traversal. | Aug 22, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-4668HIGH The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow | Oct 20, 2023 | 7.5 | 23 | NO | NO |
CVE-2015-9497HIGH The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. | Oct 22, 2019 | 8.8 | 22 | NO | NO |
CVE-2022-0901MEDIUM The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Sit | Apr 4, 2022 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ad Inserter Project.
Media articles that mention a CVE ID that affects a product developed by Ad Inserter Project — matched by CVE ID, not by vendor name.