Ajdg maintains the AdRotate advertising management plugin, a narrowly scoped product with a durable exposure pattern centered on web application input-handling flaws, particularly cross-site scripting and SQL injection vulnerabilities. These weakness classes reflect the plugin's role in processing and rendering user-supplied advertising content and database queries, attack surfaces endemic to advertisement-management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ajdg over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13570HIGH The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. | Jul 23, 2019 | 7.2 | 24 | NO | NO |
CVE-2021-24138MEDIUM Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user. | Mar 18, 2021 | 5.5 | 20 | NO | NO |
CVE-2022-0662MEDIUM The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the u | May 2, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-0649MEDIUM The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htm | May 2, 2022 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ajdg.
Media articles that mention a CVE ID that affects a product developed by Ajdg — matched by CVE ID, not by vendor name.