CVE-2026-81402
DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
| Vendor | unknown |
| Product | ds ad rotator |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ds ad rotator
Be the first to know when new critical vulnerabilities affecting unknown ds ad rotator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / DS Ad Rotator
0 โค 0.8
References
Credits
Huynh Kien Minh WPScan