CVE-2025-11745
Ad Inserter – Ad Manager & AdSense Ads
Minimum safe version
2.8.8
Update to 2.8.8 or later to address 20 fixable vulnerabilities
WordPress Ad Inserter Plugin <= 2.8.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-49248
CVE-2023-4645
CVE-2023-4668
CVE-2023-1549
Ad Inserter <= 1.5.5 - Cross-Site Request Forgery to Cross-Site Scripting
Ad Inserter < 2.7.11 - Authenticated (Admin+) Remote Code Execution
Ad Inserter <= 1.5.5 - Authenticated Cross-Site Scripting (XSS)
wpscan.com
WordPress Ad Inserter Plugin 1.5.2 - CSRF
WordPress Ad Inserter Plugin <= 1.5.5 - Cross Site Scripting
WordPress Ad Inserter plugin <= 2.4.19 - Authenticated Path Traversal vulnerability
WordPress Ad Inserter plugin <= 2.4.21 - Authenticated Remote Code Execution (RCE) vulnerability
WordPress Ad Inserter plugin <= 2.7.10 - Admin+ RCE / Stored XSS vulnerability
Ad Inserter Free and Pro <= 2.7.11 - Reflected Cross-Site Scripting
CVE-2019-15324
CVE-2019-15323
CVE-2015-9497
CVE-2022-0288