CVE · Medium

CVE-2023-4645 — Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.31

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4645 Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.31 Missing Authorization Medium 5.3 < 2.7.31 2.7.31 2023-09-22

CVE-2023-4645

The Ad Inserter plugin for WordPress contains a sensitive information disclosure flaw in versions through 2.7.30 that can be exploited through the ai_ajax function without authentication. Attackers could retrieve protected post titles, slugs, and passwords, along with usernames, available user roles, and the plugin's license key if remote debugging is turned on, though this setting is disabled by default. The vulnerability affects all unauthenticated users who can make requests to the vulnerable function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.