AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-11983

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is susceptible to an authorization bypass that allows unauthenticated attackers to access ad block contents restricted to administrators. This vulnerability poses a risk of exposing sensitive advertising configurations and data. WordPress site administrators using affected versions of the plugin should prioritize applying updates to mitigate potential exploitation.

CVE
CVE-2026-11983
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
WordPress

Original NVD Description

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.