CyberRota Analysis
AI-GeneratedThe Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is susceptible to an authorization bypass that allows unauthenticated attackers to access ad block contents restricted to administrators. This vulnerability poses a risk of exposing sensitive advertising configurations and data. WordPress site administrators using affected versions of the plugin should prioritize applying updates to mitigate potential exploitation.
Original NVD Description
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.