Tuesday, April 22, 2025
HomeInternetCritical Vulnerability in Wordpress Ad Inserter Plugin Let Hackers to Execute Arbitrary...

Critical Vulnerability in WordPress Ad Inserter Plugin Let Hackers to Execute Arbitrary PHP Code

Published on

SIEM as a Service

Follow Us on Google News

A critical remote code execution vulnerability in WordPress plugin Ad Inserter, let hackers execute arbitrary PHP code in the vulnerable installations.

The vulnerability was discovered by Wordfence security team and the vulnerability can be executed only by the authenticated users starting from Subscribers to above user levels.

The Ad Inserter used on over 200,000 websites and the functionality of the plugin to insert different kind of ads, opt-in forms and other scripts on the WordPress websites.

- Advertisement - Google News

This issue is categorized as a critical one and has CVSS Score 9.9, the websites running Ad Inserter 2.4.21 or below are affected.

Wordfence reported the vulnerability to the plugin developer and the patch was released in the next day itself, users are recommended to update with 2.4.22 right away.

With this plugin, an ad preview feature option available which let’s website administrators to see how their ad appears on the web page.

This action can be done only by the website by authenticated users and also the plugin has check_admin_referer(), which ensures the action to be done by site administrator only.

But the vulnerability discovered by Wordfence shows that security control in place: check_admin_referer() is not enough and the nonce has been compromised to get the appropriate privileges.

The Ad Inserter also includes that includes troubleshooting features, which includes a Javascript on every page, according to “Wordfence the Javascript contains a valid nonce for the ai_ajax_backend action and the debugging feature can be triggered by any user who has this special cookie.”

By having the nonce string in hand, an attacker with Subscriber or above user account can exploit the vulnerability in ad preview feature by executing malicious PHP code, explains Wordfence.

By using tools such as WPScan you can scan the WordPress sites for vulnerabilities.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Infostealer Attacks Surge 84% Weekly Through Phishing Emails

The volume of infostealer malware distributed through phishing emails has surged by 84% week-on-week...

North Korean IT Workers Use Real-Time Deepfakes to Infiltrate Organizations Through Remote Jobs

A division of Palo Alto Networks, have revealed a sophisticated scheme by North Korean...

New Phishing Technique Hides Weaponized HTML Files Within SVG Images

Cybersecurity experts have observed an alarming increase in the use of SVG (Scalable Vector...

Detecting And Blocking DNS Tunneling Techniques Using Network Analytics

DNS tunneling is a covert technique that cybercriminals use to bypass traditional network security...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit Stolen Certificates and Private Keys to Breach Organizations

Recent research has unveiled a concerning vulnerability within the realm of containerized applications, where...

Hackers Abuse Zoom’s Remote Control to Access Users’ Computers

A newly uncovered hacking campaign is targeting business leaders and cryptocurrency firms by abusing...

Speedify VPN Vulnerability on macOS Exposes Users to System Takeover

A major security flaw in the Speedify VPN application for macOS, tracked as CVE-2025-25364, has...