CVE-2022-1206

AdRotate – Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files with double extensions on the affected site's server which may make remote code execution possible. This is only exploitable on select instances where the configuration will execute the first extension present.


We have discovered 5,239 live websites that are affected by CVE-2022-1206.

Run a Free Instant Scan




Affected Software

Product  AdRotate for WordPress
Category Wordpress Plugins
Vulnerable Domains5,239 live websites (31% of AdRotate for WordPress install base)
Vulnerable Versions
  • from 0 through 5.13.2
Vulnerable Versions Count202 versions ( 82% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Aug 20, 2024
  • Updated - Apr 8, 2026

Credits

  • Jörg Steinsträter (finder)

Website Distribution by Country

Number of websites using CVE-2022-1206
United States1,832 websites



Germany484 websites
Italy330 websites
France247 websites
Russia210 websites
Japan186 websites
GB177 websites
Brazil165 websites
Poland139 websites
Canada126 websites

Website Distribution by TLD

Number of websites using CVE-2022-1206
.com2,257 websites
.it269 websites
.de241 websites
.org220 websites
.net190 websites
.ru162 websites
.com.br146 websites
.pl114 websites
.co.uk104 websites
.info80 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-1206

Top websites that are affected by CVE-2022-1206. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.de Germany**,***
*********.com United States**,***
***************.com United States**,***
**********.com United States**,***
********.com France**,***
*********.org United States**,***
******************.com United States**,***
********.com United States**,***
******************.com United States**,***
*********.*****.media Russia**,***
See full domain list

FAQ

CVE-2022-1206 is Unrestricted Upload of File with Dangerous Type in AdRotate for WordPress
A total of 5,239 websites have been identified as vulnerable to CVE-2022-1206, based on global website indexing conducted by WebTechSurvey.
The AdRotate for WordPress is affected by the CVE-2022-1206 vulnerability.
AdRotate for WordPress versions up to and including 5.13.2 are vulnerable to CVE-2022-1206.