← WordPress Vulnerabilities
WordPress security by component

DS Ad Rotator

DS Ad Rotator (ds-ad-rotator) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: ds-ad-rotator

CVE-2026-81402: DS Ad Rotator exposes an unauthenticated PHP upload handler

DS Ad Rotator through 0.8 performs no capability check, nonce verification, or file-type validation in its image upload handler. An unauthenticated attacker can upload PHP to a web-accessible directory and execute it. The authoritative export does not disclose the action name, upload field, or destination path.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for ds-ad-rotator
Safe version
Sep 12, 2026 CVE-2026-81402
DS Ad Rotator exposes an unauthenticated PHP upload handler
DS Ad Rotator through 0.8 performs no capability check, nonce verification, or file-type validation in its image upload handler. An unauthenticated attacker can upload PHP to a web-accessible directory and execute it. The authoritative export does not disclose the action name, upload field, or destination path.
See mitigation notes
CVE9.8
NVDPending