CVE-2022-1206
The AdRotate Banner Manager plugin through version 5.13.2 contains an arbitrary file upload vulnerability in the adrotate_insert_media() function stemming from inadequate file extension validation. Authenticated users with administrator privileges or higher can upload files with double extensions to the server, potentially enabling remote code execution on systems configured to execute files based on the first extension. This vulnerability was fixed in version 5.13.3.
Based on public CVE data (MITRE/NVD).