Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Adrotate — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
adrotate
- 20000+ instalaciones activas
ad manageradsadsensebannermonetize
Estado de mantenimiento
- Última versión conocida: 5.18
- Requiere PHP: 8.0+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
10 CVEs conocidos registrados para Adrotate.
Reportadas entre 2011 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-12242
|
AdRotate Banner Manager [adrotate] < 5.17.8 |
Control incorrecto de la generación de código (inyección de código) |
Alta
8,8
|
< 5.17.8
|
5.17.8 |
2026-06-23 |
✓ corregido en la última versión
|
|
CVE-2022-1206
|
AdRotate Banner Manager [adrotate] < 5.13.3 |
Carga de archivos sin restricción de tipo peligroso |
Alta
7,2
|
< 5.13.3
|
5.13.3 |
2024-08-19 |
✓ corregido en la última versión
|
|
CVE-2022-26366
|
AdRotate Banner Manager [adrotate] < 5.9.1 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 5.9.1
|
5.9.1 |
2022-11-11 |
✓ corregido en la última versión
|
|
CVE-2022-0649
|
AdRotate Banner Manager [adrotate] < 5.8.23 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 5.8.23
|
5.8.23 |
2022-04-11 |
✓ corregido en la última versión
|
|
CVE-2022-0662
|
AdRotate Banner Manager [adrotate] < 5.8.23 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 5.8.23
|
5.8.23 |
2022-04-11 |
✓ corregido en la última versión
|
|
CVE-2022-0267
|
AdRotate Banner Manager [adrotate] < 5.8.23 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 5.8.23
|
5.8.23 |
2022-02-07 |
✓ corregido en la última versión
|
|
CVE-2021-24138
|
AdRotate Banner Manager [adrotate] < 5.8.4 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Media
5,5
|
< 5.8.4
|
5.8.4 |
2020-06-03 |
✓ corregido en la última versión
|
|
—
|
AdRotate Banner Manager [adrotate] < 5.8.4 |
— |
Desconocido
|
< 5.8.4
|
5.8.4 |
2020-06-03 |
✓ corregido en la última versión
|
CVE-2026-12242
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-1206
The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-26366
The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9. This is due to missing or incorrect nonce validation on the adrotate_options() function. This makes it possible for unauthenticated attackers to invoke these functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-0649
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0662
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-0267
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24138
Authenticated SQL injection in the AdRotate 5.8.3.1 exists via param "id". However, this requires an admin privileged user.
NOTE: The plugin author mistook this SQLi bug for XSS but the remedy remains OK.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
AdRotate Banner Manager [adrotate] < 5.8.4
Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress AdRotate plugin (versions <= 5.8.3).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2019-13570
|
AdRotate Banner Manager [adrotate] < 5.3 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 5.3
|
5.3 |
2019-07-11 |
✓ corregido en la última versión
|
|
CVE-2014-1854
|
AdRotate Banner Manager [adrotate] >= 3.9 - <= 3.9.4 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Desconocido
|
3.9–3.9.5
|
3.9.5 |
2014-02-22 |
✓ corregido en la última versión
|
|
CVE-2011-4671
|
AdRotate Banner Manager [adrotate] < 3.6.8 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Desconocido
|
< 3.6.8
|
3.6.8 |
2011-09-24 |
✓ corregido en la última versión
|
CVE-2019-13570
The vendor states:
"Earlier this week I was contacted by a security research firm who has apparently been poking around in the code of AdRotate and they found an issue in AdRotate Free. Upon checking the code following their advisory I found a potential weak point in AdRotate Pro as well. Though the proof of concept "hack" didn’t work on AdRotate Pro. A few small tweaks made sense to prevent a crafty scammer to even get close.
A number of database queries have been updated to be more secure and more uniform (so the code looks prettier).
Without admin access your data is not at risk and there is no evidence that this vulnerability actually works or has been exploited anywhere."
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2014-1854
The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in versions 3.9 to 3.9.4 in the free version and 3.9 to 3.9.5 in the premium version due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2011-4671
AdRotate plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Adrotate actualizado — 5.18 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas