CyberRota Analysis
AI-GeneratedThe Advanced Ads WordPress plugin prior to version 2.0.23 is vulnerable due to inadequate sanitization and escaping of a shortcode parameter, enabling users with Contributor roles and above to inject malicious scripts. This flaw can lead to cross-site scripting (XSS) attacks, potentially affecting higher-privileged users when the compromised content is viewed. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users.