CVE-2026-12242
Description
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L265
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L276
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L288
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L265
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L276
- https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L288
- https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L265
- https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L276
- https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L288
- https://plugins.trac.wordpress.org/changeset/3582562/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f29b905c-57cf-4fb8-b6af-eb0c367cd3e4?source=cve
CWEs
CWE-94
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.