{"id":"CVE-2026-19902","title":"The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escapin…","summary":"The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escapin…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"spacetime","product":"Ad Inserter – Ad Manager & AdSense Ads","affected":["ad_inserter_ad_manager_adsense_ads <= 2.8.18"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T08:16:51.580","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19902","references":[{"url":"https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13018","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13022","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13025","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13093","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/class.php#L3297","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3709957/ad-inserter/trunk/ad-inserter.php","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3709970%40ad-inserter%2Ftags%2F2.8.19&old=3624916%40ad-inserter%2Ftags%2F2.8.18","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d632cce-40a9-4969-b213-8370ae75287e?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T08:40:11.739Z","slug":"CVE-2026-19902","body":"## Overview\n\nThe Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on the '{search-query}' dynamic tag. When an ad block's code contains that tag, replace_ai_tags() reads $_SERVER['HTTP_REFERER'] and tests it with the regex /[\\.\\/](google|yahoo|bing|ask)\\.[a-z\\.]{2,5}[\\/]/i. The leading [\\.\\/] class matches a literal slash, so any referrer merely containing a segment such as '/google.com/' passes as a search-engine referral; the plugin then percent-decodes the referring query with parse_str() and substitutes the resulting 'q' (or 'p') value into the block via preg_replace() with no escaping. This makes it possible for unauthenticated attackers to execute arbitrary JavaScript in the context of the site for any visitor, including a signed-in administrator, by luring them to an attacker-controlled page that frames or links to any ordinary post. Exploitation requires the site to have an ad block whose code uses the '{search-query}' tag with automatic insertion enabled — a documented plugin feature used as intended.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}