CVE-2026-10082 PUBLISHED

Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter

Assigner: WPScan
Reserved: 29.05.2026 Published: 27.07.2026 Updated: 27.07.2026

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users.

Product Status

Vendor Unknown
Product Advanced Ads
Versions Default: unaffected
  • affected from 0 to 2.0.23 (excl.)

Credits

  • Pablo González and Francisco José Ramírez finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE