CVE · High

CVE-2015-9497 — Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-9497 Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 1.5.3 Cross-Site Request Forgery (CSRF) High 8.8 < 1.5.3 1.5.3 2015-05-02

CVE-2015-9497

The Ad Inserter plugin for WordPress versions prior to 1.5.3 contains a cross-site request forgery vulnerability in its settings page that can be exploited to execute cross-site scripting attacks. An attacker could trick an authenticated administrator into visiting a malicious page that performs unauthorized actions on the plugin's configuration page, potentially allowing injection of malicious scripts that execute in the admin interface.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.