CVE-2026-81402
Received Received - Intake

Arbitrary File Upload in DS Ad Rotator WordPress Plugin

Vulnerability report for CVE-2026-81402, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ds_ad_rotator ds_ad_rotator to 0.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the DS Ad Rotator WordPress plugin (version 0.8 or below) allows unauthenticated attackers to upload arbitrary files, including PHP files, to a web-accessible directory due to missing capability checks, nonce verification, and file-type validation in the image upload handler.

Detection Guidance

Check if the DS Ad Rotator WordPress plugin version 0.8 or below is installed. Look for unauthorized file uploads in web-accessible directories, particularly PHP files in unexpected locations. Review server logs for suspicious upload activity or requests to the plugin's upload handler.

Impact Analysis

Attackers can exploit this to upload malicious files, such as PHP scripts, which can lead to remote code execution on the affected server, potentially allowing full control over the website or server.

Compliance Impact

This vulnerability could lead to unauthorized remote code execution, potentially exposing sensitive data stored on the server. For GDPR, this may result in unauthorized access to personal data, violating principles of data protection and user rights. For HIPAA, it could compromise protected health information if the server handles such data, leading to breaches of confidentiality and compliance violations.

Mitigation Strategies

Immediately disable or uninstall the DS Ad Rotator plugin if installed. Restrict file upload permissions in WordPress directories. Monitor for signs of exploitation and consider blocking uploads to web-accessible directories until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart