CVE detail
CVE-2026-12242
The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)Wordfence
SMTP HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-13422 Patch Status Patched Published Jun 26, 2026 Affected Software HD Quiz [hd-quiz] Researcher Wordfence PRISM More Details > Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator Majestic Support – The
vendorwww.wordfence.comJul 2, 2026, 6:34 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/f29b905c-57cf-4fb8-b6af-eb0c367cd3e4?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/changeset/3582562/plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L288plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L276plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/trunk/adrotate-output.php#L265plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L288plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L276plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.5/adrotate-output.php#L265plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L288plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L276plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM - https://plugins.trac.wordpress.org/browser/adrotate/tags/5.17.4/adrotate-output.php#L265plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-71389CVSS 10.0 · Critical
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request ha…
- CVE-2026-60122CVSS 8.5 · High
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute…
- CVE-2026-47722CVSS 8.7 · High
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the ope…
- CVE-2026-47668CVSS 10.0 · Critical
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the…
- CVE-2026-65907CVSS 9.1 · Critical
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- CVE-2026-65906CVSS 8.8 · High
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible