Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spacetime
Spacetime ad Inserter – Ad Manager & Adsense Ads Wordpress Wordpress wordpress |
|
| Vendors & Products |
Spacetime
Spacetime ad Inserter – Ad Manager & Adsense Ads Wordpress Wordpress wordpress |
Thu, 06 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility. | |
| Title | Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-06T15:00:43.027Z
Reserved: 2026-06-11T14:00:15.754Z
Link: CVE-2026-11983
Updated: 2026-08-06T15:00:37.825Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T14:15:13Z
-
CWE-862
Missing Authorization