Ad Inserter, a 300,000-install WordPress plugin, lets subscribers inject PHP
CVE-2026-81655 lets a logged-in subscriber reach an unrestricted settings page and store code that runs as PHP. Fixed in Ad Inserter 2.8.19.
Ad Inserter, a WordPress ad-management plugin with over 300,000 active installs, shipped a fix on 27 September for a code injection flaw tracked as CVE-2026-81655. Versions 2.8.12 through 2.8.18 fail to correctly restrict access to one of the plugin’s settings pages, the one for Global Custom Fields, and don’t filter what gets saved there. Any logged-in user with the lowest WordPress role, subscriber, can reach that page under configurations the plugin’s own settings allow, store code, and have it executed as PHP or served unescaped to site visitors.
It’s rated CVSS 7.5, and it’s fixed in 2.8.19, which also patches a separate stored XSS bug and an information-disclosure issue in the same release.
Why it matters: subscriber accounts are usually the ones a site hands out freely, through open registration, membership forms or a WooCommerce checkout, so “subscriber-level” doesn’t mean “trusted.” If your site takes public registrations and runs Ad Inserter, update to 2.8.19 now rather than treating this as a routine plugin bump.
The caveat: neither the CVE record nor the researcher writeups spell out exactly which configuration option exposes the page to subscribers, so it isn’t clear if it’s a default setting or something an admin has to turn on. Update regardless; the fix costs nothing either way.