plugin

Adrotate Vulnerabilities

20 known security issues reported for the Adrotate WordPress plugin. Most recent disclosed Jun 23, 2026.

2 critical 6 high 2 medium

Running Adrotate on your site? Check whether your installed version is affected.

Scan your site free

AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute

high

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code str...

CVSS:
8.8
Affected:
up to 5.17.7
Fixed in:
5.17.8
Disclosed:
Jun 23, 2026

CVE-2026-12242 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.13.3

unknown

[en] The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with admini...

Affected:
up to 5.13.3
Fixed in:
5.13.3
Disclosed:
Aug 20, 2024

CVE-2022-1206 on NVD →

AdRotate – Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload

high

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrat...

CVSS:
7.2
Affected:
up to 5.13.2
Fixed in:
5.13.3
Disclosed:
Aug 19, 2024

CVE-2022-1206 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.9.1

unknown

[en] Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.

Affected:
up to 5.9.1
Fixed in:
5.9.1
Disclosed:
Nov 30, 2022

CVE-2022-26366 on NVD →

AdRotate Banner Manager <= 5.9 - Cross-Site Request Forgery

high

The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9. This is due to missing or incorrect nonce validation on the adrotate_options() function. This makes it possible for unauthenticated attackers to invoke these functions, via forged request...

CVSS:
8.8
Affected:
up to 5.9
Fixed in:
5.9.1
Disclosed:
Nov 11, 2022

CVE-2022-26366 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.8.23

unknown

[en] The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 5.8.23
Fixed in:
5.8.23
Disclosed:
May 2, 2022

CVE-2022-0662 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.8.23

unknown

[en] The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 5.8.23
Fixed in:
5.8.23
Disclosed:
May 2, 2022

CVE-2022-0649 on NVD →

AdRotate – Ad manager & AdSense Ads <= 5.8.22 - Authenticated Stored Cross-Site Scripting via Advert Names

medium

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 5.8.23
Fixed in:
5.8.23
Disclosed:
Apr 11, 2022

CVE-2022-0662 on NVD →

AdRotate – Ad manager & AdSense Ads <= 5.8.22 - Authenticated Stored Cross-Site Scripting via Group Names

medium

The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 5.8.23
Fixed in:
5.8.23
Disclosed:
Apr 11, 2022

CVE-2022-0649 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.8.23

unknown

[en] The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

Affected:
up to 5.8.23
Fixed in:
5.8.23
Disclosed:
Mar 7, 2022

CVE-2022-0267 on NVD →

AdRotate – Ad manager & AdSense Ads <= 5.8.17 - Admin+ SQL Injection

high

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

CVSS:
7.2
Affected:
up to 5.8.17
Fixed in:
5.8.22
Disclosed:
Feb 7, 2022

CVE-2022-0267 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.8.4

unknown

[en] Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
Mar 18, 2021

CVE-2021-24138 on NVD →

AdRotate < 5.8.4 - Authenticated SQL Injection

high

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

CVSS:
7.2
Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
Jun 3, 2020

CVE-2021-24138 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.8.4

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress AdRotate plugin (versions <= 5.8.3).

Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
Jun 3, 2020

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 5.3

unknown

[en] The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

Affected:
up to 5.3
Fixed in:
5.3
Disclosed:
Jul 23, 2019

CVE-2019-13570 on NVD →

AdRotate – Ad manager & AdSense Ads <= 5.2 - Authenticated SQL Injection

high

The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

CVSS:
7.2
Affected:
up to 5.2
Fixed in:
5.3
Disclosed:
Jul 11, 2019

CVE-2019-13570 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] >= 3.9 - <= 3.9.4

unknown

[en] SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.

Affected:
3.9 – 3.9.4
Fixed in:
3.9.4
Disclosed:
Feb 27, 2014

CVE-2014-1854 on NVD →

AdRotate – Ad manager & AdSense Ads 3.9 - 3.9.4 - SQL Injection

critical

The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in versions 3.9 to 3.9.4 in the free version and 3.9 to 3.9.5 in the premium version due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...

CVSS:
9.8
Affected:
3.9 – 3.9.4
Fixed in:
3.9.5
Disclosed:
Feb 22, 2014

CVE-2014-1854 on NVD →

AdRotate Banner Manager &#8211; The only ad manager you&#039;ll need [adrotate] < 3.6.8

unknown

[en] SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).

Affected:
up to 3.6.8
Fixed in:
3.6.8
Disclosed:
Dec 2, 2011

CVE-2011-4671 on NVD →

AdRotate – Ad manager & AdSense Ads < 3.6.8 - SQL Injection

critical

SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).

CVSS:
9.8
Affected:
up to 3.6.8
Fixed in:
3.6.8
Disclosed:
Nov 8, 2011

CVE-2011-4671 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database