CVE · High

CVE-2023-4668 — Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.31

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4668 Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.31 Missing Authorization High 7.5 < 2.7.31 2.7.31 2023-09-22

CVE-2023-4668

The Ad Inserter plugin for WordPress up to version 2.7.30 contains a vulnerability allowing unauthenticated users to access sensitive information through the ai-debug-processing-fe URL parameter. By exploiting this flaw, attackers can retrieve details about installed and active plugins, the currently active theme, WordPress version, plugin configuration details, and server information such as memory limits and installation paths. This exposure of system details could enable attackers to identify further vulnerabilities or plan more targeted attacks against the WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.