CVE-2023-4668
The Ad Inserter plugin for WordPress up to version 2.7.30 contains a vulnerability allowing unauthenticated users to access sensitive information through the ai-debug-processing-fe URL parameter. By exploiting this flaw, attackers can retrieve details about installed and active plugins, the currently active theme, WordPress version, plugin configuration details, and server information such as memory limits and installation paths. This exposure of system details could enable attackers to identify further vulnerabilities or plan more targeted attacks against the WordPress installation.
Based on public CVE data (MITRE/NVD).