CVE-2026-11983
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,
CVSS
5.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 ago 2026 · Última mod.: 6 ago 2026 · CWE-862
Sin historial EPSS suficiente todavía.
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-182777.1 ALT—
———Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path7hCVE-2026-182764.3 MED—
———Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check7hCVE-2026-667127.5 ALT—
———Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.7hCVE-2026-667088.2 ALT—
———Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.8hCVE-2026-667015.3 MED—
———Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.8hCVE-2026-666995.3 MED—
———Custom role Broken Access Control in Dokan <= 5.0.10 versions.8h