VYPR

AdRotate Banner Manager

by WordPress

CVEs (1)

  • CVE-2026-12242Jun 24, 2026
    risk 0.00cvss epss

    The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute…