CVE-2026-11983 MEDIUM

CVE-2026-11983: Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax

Vendor Spacetime
Product Ad Inserter – Ad Manager & AdSense Ads
Weakness CWE-862 · Missing authorization
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.

Explanation of Vulnerability in Simple Terms

02Summary

Ad Inserter versions 2.8.16 and earlier lack proper authorization checks, allowing unauthenticated attackers to read sensitive information. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 2.8.16 to prevent unauthorized data disclosure.

What an attacker can do

03Attacker Capabilities

Read sensitive data without logging in.

Potential impact on your site

04Site Impact

Attackers can access confidential information exposed by the plugin without needing an account.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE