CVE-2023-4645
The Ad Inserter plugin for WordPress contains a sensitive information disclosure flaw in versions through 2.7.30 that can be exploited through the ai_ajax function without authentication. Attackers could retrieve protected post titles, slugs, and passwords, along with usernames, available user roles, and the plugin's license key if remote debugging is turned on, though this setting is disabled by default. The vulnerability affects all unauthenticated users who can make requests to the vulnerable function.
Based on public CVE data (MITRE/NVD).