CVE · High

CVE-2022-1206 — AdRotate Banner Manager [adrotate] < 5.13.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1206 AdRotate Banner Manager [adrotate] < 5.13.3 Unrestricted Upload of File with Dangerous Type High 7.2 < 5.13.3 5.13.3 2024-08-19

CVE-2022-1206

The AdRotate Banner Manager plugin through version 5.13.2 contains an arbitrary file upload vulnerability in the adrotate_insert_media() function stemming from inadequate file extension validation. Authenticated users with administrator privileges or higher can upload files with double extensions to the server, potentially enabling remote code execution on systems configured to execute files based on the first extension. This vulnerability was fixed in version 5.13.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.