What is CVE-2026-10082?
CVE-2026-10082 is a stored XSS vulnerability in the Advanced Ads WordPress plugin where a shortcode parameter is not sanitized before output. It affects versions before 2.0.23, allowing users with Contributor role and above to inject arbitrary web scripts that execute when viewed, including by higher-privileged users. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-10082, Advanced Ads WordPress plaginində qısa kod (shortcode) parametrinin sanitizasiya edilməməsi ilə bağlı saxlanmış XSS zəifliyidir. 2.0.23 versiyasından əvvəlki versiyalar təsirlənir, Contributor və yuxarı roluna malik istifadəçilərə yüksək imtiyazlı istifadəçilər də daxil olmaqla səhifədə ixtiyari skript icra etməyə imkan verir. Plaqinin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which functional component of the Advanced Ads plugin is affected by CVE-2026-10082?
CVE-2026-10082 affects a shortcode parameter in the Advanced Ads WordPress plugin that is not sanitized.
What is the minimum user role an attacker needs to exploit CVE-2026-10082?
An attacker needs at least a Contributor role or above to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.