The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.
We have discovered 9,659 live websites that are affected by CVE-2022-1206.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 9,659 live websites (46.78% of AdRotate for WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 229 versions ( 88.08% of all versions) |
![]() | 4,174 websites |
![]() | 895 websites |
![]() | 470 websites |
![]() | 410 websites |
![]() | 367 websites |
![]() | 331 websites |
![]() | 267 websites |
![]() | 260 websites |
![]() | 242 websites |
![]() | 164 websites |
.com | 4,458 websites |
.de | 396 websites |
.net | 383 websites |
.org | 356 websites |
.com.br | 334 websites |
.it | 326 websites |
.ru | 284 websites |
.pl | 210 websites |
.co.uk | 165 websites |
.ca | 145 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********************.com | ![]() | *,*** | |
**************.se | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
*********.de | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.com | ![]() | **,*** |
FAQ