SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-10082

MEDIUM · CVSS 6.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Advanced Ads WordPress plugin prior to version 2.0.23 is vulnerable due to inadequate sanitization and escaping of a shortcode parameter, enabling users with Contributor roles and above to inject malicious scripts. This flaw can lead to cross-site scripting (XSS) attacks, potentially affecting higher-privileged users when the compromised content is viewed. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-10082
Severity
MEDIUM
CVSS
6.1
EPSS
0.14%
WordPress

Original NVD Description

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users.