ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-0662
+1 in the same advisory: …0649
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting att

The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

NVD description · AI analysis pending
4.8<1% PoC
  • ajdg adrotate
CVE-2021-24138
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id".

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

NVD description · AI analysis pending
5.51% PoC
  • ajdg adrotate
CVE-2019-13570
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

NVD description · AI analysis pending
7.22%
  • ajdg adrotate