CVE-2026-81402
The DS Ad Rotator WordPress plugin up to version 0.8 has a serious flaw that lets anyone upload any file, including PHP scripts, to the site without permission. This can let attackers run code on the server.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites using the DS Ad Rotator plugin version 0.8 or earlier.
Real-world impact
An attacker could upload a malicious PHP file and then execute it, giving them full control over the website, allowing data theft, defacement, or further attacks.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network, requires no user interaction, and can compromise confidentiality, integrity, and availability.
What to do about it
- ›Disable or remove the DS Ad Rotator plugin until a patched version is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.