Extension WordPress
Vulnérabilités AdRotate Banner Manager
Cette page rassemble les failles publiées pour AdRotate Banner Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AdRotate Banner Manager
10 fiches
AdRotate Banner Manager <= 5.17.7 – Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization…
*-5.17.7
5.17.8
23/06/2026
AdRotate – Ad manager & AdSense Ads <= 5.13.2 – Authenticated (Admin+) Double Extension Arbitrary File Upload
The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2.…
*-5.13.2
5.13.3
19/08/2024
AdRotate Banner Manager <= 5.9 – Cross-Site Request Forgery
The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9. This is due to missing or incorrect nonce validation on the adrotate_options() function. This makes it possible for…
*-5.9
5.9.1
11/11/2022
AdRotate – Ad manager & AdSense Ads <= 5.8.22 – Authenticated Stored Cross-Site Scripting via Advert Names
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 5.8.23)
5.8.23
11/04/2022
AdRotate – Ad manager & AdSense Ads <= 5.8.22 – Authenticated Stored Cross-Site Scripting via Group Names
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 5.8.23)
5.8.23
11/04/2022
AdRotate – Ad manager & AdSense Ads <= 5.8.17 – Admin+ SQL Injection
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
*-5.8.17
5.8.22
07/02/2022
AdRotate < 5.8.4 – Authenticated SQL Injection
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
[*, 5.8.4)
5.8.4
03/06/2020
AdRotate – Ad manager & AdSense Ads <= 5.2 – Authenticated SQL Injection
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
*-5.2
5.3
11/07/2019
AdRotate – Ad manager & AdSense Ads 3.9 – 3.9.4 – SQL Injection
The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in versions 3.9 to 3.9.4 in the free version and 3.9 to 3.9.5 in the premium version due to insufficient…
3.9-3.9.4
3.9.5
22/02/2014
AdRotate – Ad manager & AdSense Ads < 3.6.8 – SQL Injection
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).
[*, 3.6.8)
3.6.8
08/11/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.