CVE-2026-12242

AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.


We have discovered 13,768 live websites that are affected by CVE-2026-12242.

Run a Free Instant Scan




Affected Software

Product  AdRotate for WordPress
Category Wordpress Plugins
Vulnerable Domains13,768 live websites (82% of AdRotate for WordPress install base)
Vulnerable Versions
  • from 0 through 5.17.7
Vulnerable Versions Count223 versions ( 90% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Jun 24, 2026
  • Updated - Jun 24, 2026

Credits

  • Osvaldo Noe Gonzalez Del Rio (finder)

Website Distribution by Country

Number of websites using CVE-2026-12242
United States5,175 websites



Germany1,214 websites
Italy761 websites
Brazil616 websites
Japan602 websites
GB481 websites
France467 websites
Russia382 websites
Poland316 websites
Canada300 websites

Website Distribution by TLD

Number of websites using CVE-2026-12242
.com6,021 websites
.org655 websites
.it619 websites
.de612 websites
.com.br582 websites
.net485 websites
.ru306 websites
.pl261 websites
.co.uk252 websites
.nl211 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12242

Top websites that are affected by CVE-2026-12242. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States**,***
*********.de Germany**,***
*********************.com United States**,***
***.org United States**,***
***************.com United States**,***
**********.com United States**,***
****.*********.com United States**,***
************.com United States**,***
******.ca Canada**,***
*************.com United States**,***
See full domain list

FAQ

CVE-2026-12242 is Improper Control of Generation of Code ('Code Injection') in AdRotate for WordPress
A total of 13,768 websites have been identified as vulnerable to CVE-2026-12242, based on global website indexing conducted by WebTechSurvey.
The AdRotate for WordPress is affected by the CVE-2026-12242 vulnerability.
AdRotate for WordPress versions up to and including 5.17.7 are vulnerable to CVE-2026-12242.

References