Loading market data...
← Back to CVE feed

CVE-2026-81655

HIGH CVSS 7.5 View on NVD ↗

Description

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Sep 27, 2026 06:16 UTC Modified: Sep 28, 2026 02:17 UTC