CVE · High

CVE-2026-12242 — AdRotate Banner Manager [adrotate] < 5.17.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12242 AdRotate Banner Manager [adrotate] < 5.17.8 Improper Control of Generation of Code ('Code Injection') High 8.8 < 5.17.8 5.17.8 2026-06-23

CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress contains a security flaw that allows attackers with at least contributor privileges to inject malicious PHP code into the system through the 'banner' attribute of the adrotate shortcode, provided that either W3 Total Cache or Borlabs Cache is activated within the plugin's settings. This occurs because the input from this attribute is not properly validated and sanitized before being combined with other code. As a result, attackers can execute arbitrary PHP commands on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.