---
id: CVE-2026-81655
title: >-
  The Ad Inserter  WordPress plugin before 2.8.19 does not correctly restrict
  access to one of its settings pages, making it reachable by every logged in
  user under a configuration its own settings allow, and does not filter the
  content sa…
summary: >-
  The Ad Inserter  WordPress plugin before 2.8.19 does not correctly restrict
  access to one of its settings pages, making it reachable by every logged in
  user under a configuration its own settings allow, and does not filter the
  content sa…
severity: none
cwe:
  - CWE-94
  - CWE-79
product: Ad Inserter
affected:
  - ad_inserter >= 2.8.12 < 2.8.19
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:16:58.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81655'
references:
  - url: 'https://wpscan.com/vulnerability/b189ce9a-a930-41e6-bdd1-fdcc3bfb66be/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.827Z'
---

## Overview

The Ad Inserter  WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
