PT-2026-51786 · WordPress+1 · Adrotate Banner Manager+2
CVE-2026-12242
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AdRotate Banner Manager versions prior to 5.17.8
Description
Insufficient input validation and sanitization of the
banner attribute within the adrotate shortcode allows authenticated attackers with Contributor-level access or higher to execute arbitrary PHP code on the server. This occurs when the attribute is concatenated into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This issue is only exploitable if W3 Total Cache or Borlabs Cache support is enabled in the settings.Recommendations
Update AdRotate Banner Manager to version 5.17.8 or later.
Disable W3 Total Cache or Borlabs Cache support in the AdRotate settings as a temporary mitigation measure.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adrotate Banner Manager
Borlabs Cache
W3 Total Cache