← Back

Adrotate

adrotate

Vendor: Ajdg • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ajdg
1Adrotate
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Ajdg
1Adrotate
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
1Ajdg
1Adrotate
Jun 17, 2026
Mar 18, 2021
N/A· v4
5.5 MEDIUM· v3
5.5 MEDIUM· v2
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
1Ajdg
1Adrotate
Jun 17, 2026
Jul 23, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.