Access violation vulnerability in Ad Inserter – Ad Manager & AdSense Ads 2.7.30

The Ad Inserter for WordPress, a plugin used to manage ads on WordPress websites, is vulnerable to Sensitive Information Exposure. Versions of the plugin up to and including 2.7.30 are affected. An unauthenticated attacker (someone not logged in) can use a specific URL parameter, called ai-debug-processing-fe, to extract sensitive data from the website. This data can include details about installed plugins (present and active), active theme, various plugin settings, WordPress version, and even some server settings such as memory limit and installation paths.

Detected in:

Ad Inserter – Ad Manager & AdSense Ads fixed vulnerable versions: >= * <= 2.7.30

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.