CVE Database /
CVE-2015-9497
CVE · High
CVE-2015-9497 — Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 1.5.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2015-9497
|
Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 1.5.3 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 1.5.3
|
1.5.3 |
2015-05-02 |
—
|
CVE-2015-9497
The Ad Inserter plugin for WordPress versions prior to 1.5.3 contains a cross-site request forgery vulnerability in its settings page that can be exploited to execute cross-site scripting attacks. An attacker could trick an authenticated administrator into visiting a malicious page that performs unauthorized actions on the plugin's configuration page, potentially allowing injection of malicious scripts that execute in the admin interface.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings