Critical Vulnerability in WordPress Ad Inserter Plugin Let Hackers to Execute Arbitrary PHP Code

A critical remote code execution vulnerability in WordPress plugin Ad Inserter, let hackers execute arbitrary PHP code in the vulnerable installations.

The vulnerability was discovered by Wordfence security team and the vulnerability can be executed only by the authenticated users starting from Subscribers to above user levels.

The Ad Inserter used on over 200,000 websites and the functionality of the plugin to insert different kind of ads, opt-in forms and other scripts on the WordPress websites.

This issue is categorized as a critical one and has CVSS Score 9.9, the websites running Ad Inserter 2.4.21 or below are affected.

Wordfence reported the vulnerability to the plugin developer and the patch was released in the next day itself, users are recommended to update with 2.4.22 right away.

With this plugin, an ad preview feature option available which let’s website administrators to see how their ad appears on the web page.

This action can be done only by the website by authenticated users and also the plugin has check_admin_referer(), which ensures the action to be done by site administrator only.

But the vulnerability discovered by Wordfence shows that security control in place: check_admin_referer() is not enough and the nonce has been compromised to get the appropriate privileges.

The Ad Inserter also includes that includes troubleshooting features, which includes a Javascript on every page, according to “Wordfence the Javascript contains a valid nonce for the ai_ajax_backend action and the debugging feature can be triggered by any user who has this special cookie.”

By having the nonce string in hand, an attacker with Subscriber or above user account can exploit the vulnerability in ad preview feature by executing malicious PHP code, explains Wordfence.

By using tools such as WPScan you can scan the WordPress sites for vulnerabilities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection vulnerability…

2 hours ago

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from networks…

2 hours ago

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform that…

4 hours ago

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has been…

5 hours ago

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000 Series…

5 hours ago

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver Fox,…

14 hours ago