CVE-2022-1206

AdRotate – Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.


We have discovered 9,659 live websites that are affected by CVE-2022-1206.

Test my site




Affected Software

Product  AdRotate for WordPress
Category Wordpress Plugins
Vulnerable Domains9,659 live websites (46.78% of AdRotate for WordPress install base)
Vulnerable Versions
  • from 0 through 5.13.2
Vulnerable Versions Count229 versions ( 88.08% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Aug 20, 2024
  • Updated - Sep 13, 2024

Credits

  • Jörg Steinsträter (finder)

CVE-2022-1206 usage by Country

United States4,174 websites



Germany895 websites
Japan470 websites
France410 websites
Italy367 websites
Russia331 websites
GB267 websites
Brazil260 websites
Poland242 websites
Spain164 websites

CVE-2022-1206 usage by TLD

.com4,458 websites
.de396 websites
.net383 websites
.org356 websites
.com.br334 websites
.it326 websites
.ru284 websites
.pl210 websites
.co.uk165 websites
.ca145 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-1206

Top websites that are affected by CVE-2022-1206. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********************.com United States*,***
**************.se Sweden**,***
*****************.com United States**,***
**************.com United States**,***
*********.de United States**,***
*********.com United States**,***
***************.com United States**,***
***********.com United States**,***
**********.com United States**,***
********.com France**,***
See full domain list

FAQ

CVE-2022-1206 is Unrestricted Upload of File with Dangerous Type in AdRotate for WordPress
A total of 9,659 websites have been identified as vulnerable to CVE-2022-1206, discovered through global website indexing conducted by WebTechSurvey.
AdRotate for WordPress is susceptible to CVE-2022-1206 vulnerability.
AdRotate for WordPress versions before, and including, 5.13.2 are vulnerable to CVE-2022-1206.