Executive brief
The DS Ad Rotator WordPress plugin, used to manage ad placements on websites, contains an image upload function that does not verify user identity or validate file types. An unauthenticated attacker can upload malicious files—including executable PHP scripts—directly to the web server, enabling them to execute code and gain complete control over the affected website and its data.
Technical details
The vulnerability is an unauthenticated arbitrary file upload in the image upload handler of the DS Ad Rotator WordPress plugin through version 0.8. The vulnerable code lacks three critical security checks: capability verification (WordPress permission checks), nonce verification (CSRF tokens), and file-type validation. An attacker can reach the upload endpoint over the network without authentication and upload a PHP file to a web-accessible directory, allowing remote code execution (RCE) with web server privileges. No patch is currently available for versions 0.8 and earlier.
Affected products
- DS Ad Rotator (WPScan) DS Ad Rotator through 0.8
Timeline
- 2026-09-10: disclosed: Publicly disclosed on WPScan
- 2026-10-01: other: Proof of concept scheduled for public release