CVE 8.8 HIGH

AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute_CVE-2026-12242

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.

AI Analysis

PHP Code Injection vulnerability in AdRotate Banner Manager plugin via 'banner' shortcode attribute

Basic Information

ID CVE-2026-12242
Source Wordfence
Published Jun 24, 2026 at 12:33

Affected Product

Vendor adegans
Product AdRotate Banner Manager
Affected Versions adegans AdRotate Banner Manager 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor adegans
Product AdRotate Banner Manager
Version <= 5.17.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.