cleantalk
Vulnerabilities and Security Researches

AdRotate Banner Manager – The only ad manager you'll need, CVE-2022-0662

CVE, Research URL

CVE-2022-0662

Published on
May 02, 2022
Research Description
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected versions
max 5.8.23.
Status
vulnerable