PT-2026-51786 · WordPress+1 · Adrotate Banner Manager+2

CVE-2026-12242

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdRotate Banner Manager versions prior to 5.17.8
Description Insufficient input validation and sanitization of the banner attribute within the adrotate shortcode allows authenticated attackers with Contributor-level access or higher to execute arbitrary PHP code on the server. This occurs when the attribute is concatenated into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This issue is only exploitable if W3 Total Cache or Borlabs Cache support is enabled in the settings.
Recommendations Update AdRotate Banner Manager to version 5.17.8 or later. Disable W3 Total Cache or Borlabs Cache support in the AdRotate settings as a temporary mitigation measure.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12242

Affected Products

Adrotate Banner Manager
Borlabs Cache
W3 Total Cache