Security Warning: Critical vulnerabilities inWordPress(CVE-2026-12415, CVE-2026-12242, CVE-2026-5305)
Discovering three major vulnerabilities inWordPressplugins: Invoice Generator, AdRotate Banner Manager and Email Address Encoder. Understand the impact and take action to...
Recently, three major vulnerabilities have been published in theWordPressplugins, which can have a significant impact on website security. These vulnerabilities, identified with CVE-2026-12415, CVE-2026-12242 and CVE-2026-5305, affect the Invoice Generator plugins, AdRotate Banner Manager and Email Address Encoder, respectively. In this article, we will explore the details of each vulnerability and provide concrete recommendations for protecting websites.
CVE-2026-12415: Escalating Privileges in Invoice Generator
The CVE-2026-12415 vulnerability with a critical severity and a score of 9.8 affects the Invoice Generator plugin forWordPress. The problem lies in the lack of capability verification for the AJAX action pravel_invoice_edit_account, which allows unauthorized attackers to change the email address of any user, including administrators. This can lead to loss of control over the account and unauthorized access to the website.
To prevent exploitation of this vulnerability, it is essential to update the Invoice Generator plugin to the latest version available. It is also recommended to periodically check for user accounts and suspicious activities on the website.
CVE-2026-12242: Injecting PHP code into AdRotate Banner Manager
The CVE-2026-12242 vulnerability with a high severity and 8.8 score affects the AdRotate Banner Manager plugin forWordPress. The problem lies in the insufficient validation and sanitation of the ‘banner’ attribute of the adroted shortcut, which allows authenticated attackers, with contributor level or higher access, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support activated in AdRotate settings.
To prevent exploitation of this vulnerability, it is recommended to update the AdRotate Banner Manager plugin to the latest available version and disable W3 Total Cache and Borlabs Cache support if not necessary.
CVE-2026-5305: XSS attacks stored in Email Address Encoder
The CVE-2026-5305 vulnerability, with a high severity and 8.8 score, affects the Email Address Encoder plugin forWordPress. The problem lies in the incorrect handling of email replacement, which allows unauthenticated attackers to perform stored XSS attacks.
To prevent exploitation of this vulnerability, it is recommended to update the Email Address Encoder plugin to the latest available version and periodically check the code and content of the website to detect any suspicious activity.
What can you do today
-
Updates allWordPressplugins to the latest available versions
-
Periodically checks user accounts and suspicious activities on the website
-
Disable W3 Total Cache and Borlabs Cache support if not needed
-
Check the website code and content to detect any suspicious activity
Monitoring and protecting websites are essential for preventing cyber attacks.Zebrabyteprovides advanced security solutions including monitoring and protection against cyber attacks. Contact us to learn more about how we can help protect your website.
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.