CVE-2026-12242
The AdRotate Banner Manager plugin for WordPress contains a security flaw that allows attackers with at least contributor privileges to inject malicious PHP code into the system through the 'banner' attribute of the adrotate shortcode, provided that either W3 Total Cache or Borlabs Cache is activated within the plugin's settings. This occurs because the input from this attribute is not properly validated and sanitized before being combined with other code. As a result, attackers can execute arbitrary PHP commands on the server.
Based on public CVE data (MITRE/NVD).