WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Ad Inserter – Ad Manager & AdSense Ads

Manage Google AdSense ads, banners, ad rotation, sticky widgets, AMP ads, ads.txt, tracking, header and footer code, PHP code, global custom fields

16Reported vulnerabilities
8.8Highest CVSS score
2.8.18Latest version
300,000+Active installs

What to do now

Update Ad Inserter – Ad Manager & AdSense Ads to 2.8.17 or later. 16 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 27, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-1549 High 7.2 16.9% Before 2.7.27 2.7.27 May 15, 2023
CVE-2019-15324 High 8.8 3.6% Before 2.4.22 2.4.22 August 22, 2019
CVE-2015-9497 High 8.8 1.0% Before 1.5.3 1.5.3 October 22, 2019
CVE-2019-15323 High 7.5 2.0% Before 2.4.20 2.4.20 August 22, 2019
CVE-2023-4668 High 7.5 0.5% Before 2.7.31 2.7.31 October 20, 2023
CVE-2022-0901 Medium 6.1 3.6% Before 2.7.12 2.7.12 April 7, 2022
WF-a596c9c4-ceb4-470c-8ad5-986cd62da91e High 7.2 Before 2.7.11 2.7.11 February 3, 2022
CVE-2026-57693 Medium 6.4 0.2% 2.8.11 and earlier 2.8.12 July 8, 2026
CVE-2025-11745 Medium 6.4 0.2% 0 to 2.8.7 (inclusive) 2.8.8 November 5, 2025
CVE-2026-9280 Medium 6.1 0.4% 0 to 2.8.15 (inclusive) 2.8.16 June 6, 2026
CVE-2025-22623 Medium 6.1 0.4% 2.8.0 and earlier 2.8.1 March 5, 2025
CVE-2024-49248 Medium 6.1 0.3% 2.7.37 and earlier 2.7.38 October 14, 2024
CVE-2023-4645 Medium 5.3 0.6% 2.7.30 and earlier 2.7.31 October 19, 2023
CVE-2026-11983 Medium 5.3 0.3% 2.8.16 and earlier 2.8.17 August 5, 2026
WF-427c29e6-9bbe-4094-a2a2-46945525f5b3 Medium 4.8 1.5.5 and earlier 1.5.6 August 13, 2015
CVE-2026-11900 Medium 4.3 0.5% 0 to 2.8.16 (inclusive) 2.8.17 July 3, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.