WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Adrotate?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Adrotate — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: adrotate
  • 20000+ instalaciones activas

ad manageradsadsensebannermonetize

Estado de mantenimiento

  • Última versión conocida: 5.18
  • Requiere PHP: 8.0+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

10 CVEs conocidos registrados para Adrotate. Reportadas entre 2011 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-12242 AdRotate Banner Manager [adrotate] < 5.17.8 Control incorrecto de la generación de código (inyección de código) Alta 8,8 < 5.17.8 5.17.8 2026-06-23 ✓ corregido en la última versión
CVE-2022-1206 AdRotate Banner Manager [adrotate] < 5.13.3 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 5.13.3 5.13.3 2024-08-19 ✓ corregido en la última versión
CVE-2022-26366 AdRotate Banner Manager [adrotate] < 5.9.1 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 5.9.1 5.9.1 2022-11-11 ✓ corregido en la última versión
CVE-2022-0649 AdRotate Banner Manager [adrotate] < 5.8.23 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 5.8.23 5.8.23 2022-04-11 ✓ corregido en la última versión
CVE-2022-0662 AdRotate Banner Manager [adrotate] < 5.8.23 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 5.8.23 5.8.23 2022-04-11 ✓ corregido en la última versión
CVE-2022-0267 AdRotate Banner Manager [adrotate] < 5.8.23 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,2 < 5.8.23 5.8.23 2022-02-07 ✓ corregido en la última versión
CVE-2021-24138 AdRotate Banner Manager [adrotate] < 5.8.4 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Media 5,5 < 5.8.4 5.8.4 2020-06-03 ✓ corregido en la última versión
AdRotate Banner Manager [adrotate] < 5.8.4 Desconocido < 5.8.4 5.8.4 2020-06-03 ✓ corregido en la última versión

CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-1206

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-26366

The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9. This is due to missing or incorrect nonce validation on the adrotate_options() function. This makes it possible for unauthenticated attackers to invoke these functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-0649

The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0662

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0267

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24138

Authenticated SQL injection in the AdRotate 5.8.3.1 exists via param "id". However, this requires an admin privileged user. NOTE: The plugin author mistook this SQLi bug for XSS but the remedy remains OK.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

AdRotate Banner Manager [adrotate] < 5.8.4

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress AdRotate plugin (versions <= 5.8.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 3 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2019-13570 AdRotate Banner Manager [adrotate] < 5.3 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,2 < 5.3 5.3 2019-07-11 ✓ corregido en la última versión
CVE-2014-1854 AdRotate Banner Manager [adrotate] >= 3.9 - <= 3.9.4 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Desconocido 3.9–3.9.5 3.9.5 2014-02-22 ✓ corregido en la última versión
CVE-2011-4671 AdRotate Banner Manager [adrotate] < 3.6.8 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Desconocido < 3.6.8 3.6.8 2011-09-24 ✓ corregido en la última versión

CVE-2019-13570

The vendor states: "Earlier this week I was contacted by a security research firm who has apparently been poking around in the code of AdRotate and they found an issue in AdRotate Free. Upon checking the code following their advisory I found a potential weak point in AdRotate Pro as well. Though the proof of concept "hack" didn’t work on AdRotate Pro. A few small tweaks made sense to prevent a crafty scammer to even get close. A number of database queries have been updated to be more secure and more uniform (so the code looks prettier). Without admin access your data is not at risk and there is no evidence that this vulnerability actually works or has been exploited anywhere."

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2014-1854

The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in versions 3.9 to 3.9.4 in the free version and 3.9 to 3.9.5 in the premium version due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2011-4671

AdRotate plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Mantén Adrotate actualizado — 5.18 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.