The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.
We have discovered 13,768 live websites that are affected by CVE-2026-12242.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 13,768 live websites (82% of AdRotate for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 223 versions ( 90% of all versions) |
| 5,175 websites | |
| 1,214 websites | |
| 761 websites | |
| 616 websites | |
| 602 websites | |
| 481 websites | |
| 467 websites | |
| 382 websites | |
| 316 websites | |
| 300 websites |
| .com | 6,021 websites |
| .org | 655 websites |
| .it | 619 websites |
| .de | 612 websites |
| .com.br | 582 websites |
| .net | 485 websites |
| .ru | 306 websites |
| .pl | 261 websites |
| .co.uk | 252 websites |
| .nl | 211 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.com | **,*** | ||
| *********.de | **,*** | ||
| *********************.com | **,*** | ||
| ***.org | **,*** | ||
| ***************.com | **,*** | ||
| **********.com | **,*** | ||
| ****.*********.com | **,*** | ||
| ************.com | **,*** | ||
| ******.ca | **,*** | ||
| *************.com | **,*** |
FAQ