AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
high
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code str...
- CVSS:
- 8.8
- Affected:
- up to 5.17.7
- Fixed in:
- 5.17.8
- Disclosed:
- Jun 23, 2026
CVE-2026-12242 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.13.3
unknown
[en] The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with admini...
- Affected:
- up to 5.13.3
- Fixed in:
- 5.13.3
- Disclosed:
- Aug 20, 2024
CVE-2022-1206 on NVD →
AdRotate – Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload
high
The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrat...
- CVSS:
- 7.2
- Affected:
- up to 5.13.2
- Fixed in:
- 5.13.3
- Disclosed:
- Aug 19, 2024
CVE-2022-1206 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.9.1
unknown
[en] Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.
- Affected:
- up to 5.9.1
- Fixed in:
- 5.9.1
- Disclosed:
- Nov 30, 2022
CVE-2022-26366 on NVD →
AdRotate Banner Manager <= 5.9 - Cross-Site Request Forgery
high
The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9. This is due to missing or incorrect nonce validation on the adrotate_options() function. This makes it possible for unauthenticated attackers to invoke these functions, via forged request...
- CVSS:
- 8.8
- Affected:
- up to 5.9
- Fixed in:
- 5.9.1
- Disclosed:
- Nov 11, 2022
CVE-2022-26366 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.8.23
unknown
[en] The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 5.8.23
- Fixed in:
- 5.8.23
- Disclosed:
- May 2, 2022
CVE-2022-0662 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.8.23
unknown
[en] The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 5.8.23
- Fixed in:
- 5.8.23
- Disclosed:
- May 2, 2022
CVE-2022-0649 on NVD →
AdRotate – Ad manager & AdSense Ads <= 5.8.22 - Authenticated Stored Cross-Site Scripting via Advert Names
medium
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 5.8.23
- Fixed in:
- 5.8.23
- Disclosed:
- Apr 11, 2022
CVE-2022-0662 on NVD →
AdRotate – Ad manager & AdSense Ads <= 5.8.22 - Authenticated Stored Cross-Site Scripting via Group Names
medium
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 5.8.23
- Fixed in:
- 5.8.23
- Disclosed:
- Apr 11, 2022
CVE-2022-0649 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.8.23
unknown
[en] The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
- Affected:
- up to 5.8.23
- Fixed in:
- 5.8.23
- Disclosed:
- Mar 7, 2022
CVE-2022-0267 on NVD →
AdRotate – Ad manager & AdSense Ads <= 5.8.17 - Admin+ SQL Injection
high
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
- CVSS:
- 7.2
- Affected:
- up to 5.8.17
- Fixed in:
- 5.8.22
- Disclosed:
- Feb 7, 2022
CVE-2022-0267 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.8.4
unknown
[en] Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.4
- Disclosed:
- Mar 18, 2021
CVE-2021-24138 on NVD →
AdRotate < 5.8.4 - Authenticated SQL Injection
high
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
- CVSS:
- 7.2
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.4
- Disclosed:
- Jun 3, 2020
CVE-2021-24138 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.8.4
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress AdRotate plugin (versions <= 5.8.3).
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.4
- Disclosed:
- Jun 3, 2020
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 5.3
unknown
[en] The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
- Affected:
- up to 5.3
- Fixed in:
- 5.3
- Disclosed:
- Jul 23, 2019
CVE-2019-13570 on NVD →
AdRotate – Ad manager & AdSense Ads <= 5.2 - Authenticated SQL Injection
high
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
- CVSS:
- 7.2
- Affected:
- up to 5.2
- Fixed in:
- 5.3
- Disclosed:
- Jul 11, 2019
CVE-2019-13570 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] >= 3.9 - <= 3.9.4
unknown
[en] SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.
- Affected:
- 3.9 – 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Feb 27, 2014
CVE-2014-1854 on NVD →
AdRotate – Ad manager & AdSense Ads 3.9 - 3.9.4 - SQL Injection
critical
The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in versions 3.9 to 3.9.4 in the free version and 3.9 to 3.9.5 in the premium version due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...
- CVSS:
- 9.8
- Affected:
- 3.9 – 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Feb 22, 2014
CVE-2014-1854 on NVD →
AdRotate Banner Manager – The only ad manager you'll need [adrotate] < 3.6.8
unknown
[en] SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Dec 2, 2011
CVE-2011-4671 on NVD →
AdRotate – Ad manager & AdSense Ads < 3.6.8 - SQL Injection
critical
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).
- CVSS:
- 9.8
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Nov 8, 2011
CVE-2011-4671 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database