CVE-2026-12242 - AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
CVE ID :CVE-2026-12242 Published : June 24, 2026, 12:33 p.m. | 4 hours, 37 minutes ago Description :The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is...