Wp-Insert

Wp-Insert has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2023; all 2 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.

Every one of the 2 issues recorded for Wp-Insert has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Wp-Insert is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.1/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Wp-Insert vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2018-17573

Wp-Insert <= 2.4.2 - Arbitrary File Upload

Read the full analysis

Vulnerability Records

2 records
Wp-Insert banner
Latestv2.6.0
4.5(142)
90/100
Last Updated
2026-07-30 (1mo ago)
Active Installs
9,000+
Downloads
770,083
Requires WP
6.3+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2009-05-05 (18y ago)

Wp-Insert is a powerful yet easy to use ad management / ad insertion plugin which does a lot more than ad management and insertion. Ad code from any network — AdSense, iframes, JavaScript snippets or plain HTML — is inserted exactly as you provide it. Features Adsense optimised, with support for Auto Ads / Page-Level ads Unlimited ad blocks, with no artificial restrictions Insert ads above, below, to the left, to the right, or in the middle of post content with intelligent midpoint detection Insert ads after a chosen number of paragraphs, counting from the top or the bottom Insert ads into sidebars using ad widgets Insert ads into post content using shortcodes Insert ads directly into theme files, with the rules system still applied Gutenberg blocks for manual ad placement GUI driven rules system controlling when and where ads appear Exclude ads from specific posts, pages, categories, archives, search and 404 pages Hide ads for logged-in users or for mobile visitors Per-device targeting and styling for large desktop, medium desktop, tablet and mobile A/B testing across up to three ad networks, so only one network’s ads appear at a time Country specific ad placement using a bundled, offline IP-to-country database Insert Google Analytics, Facebook Pixel or any other tracking code into the header or footer Supports shortcodes from other plugins inside ad blocks Authorized Digital Sellers (ads.txt) management with daily AdSense publisher-ID monitoring Legal page templates (Privacy Policy, Terms & Conditions, Disclaimer, Copyright) to kick-start your legal pages Compatible with the AMP plugin by Automattic and WooCommerce aware External Services This plugin does not send visitor data to any external service. Country based ad targeting is resolved locally using an IP-to-country database bundled with the plugin, so no visitor IP address leaves your server. Earlier versions of Wp-Insert used the third-party freegeoip.net / ipstack APIs for this feature; that is no longer the case. Ad code that you add through the plugin may itself load resources from your ad network (for example Google AdSense). Those requests are made by the ad code you supply, are governed by that network’s own privacy policy, and are entirely under your control.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C