VYPR

AdRotate Banner Manager

by WordPress

CVEs (3)

  • CVE-2026-12242HigJun 24, 2026
    risk 0.50cvss 8.8epss 0.00

    The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute…

  • CVE-2022-1206HigAug 20, 2024
    risk 0.40cvss 7.2epss 0.01

    The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible…

  • CVE-2022-26366MedNov 30, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.