AdRotate Banner Manager 5.13 – Security and bugfix update

AdRotate Banner Manager 5.13 fixes a number of bugs including a low level XSS vulnerability. To be safe you should update as soon as possible. AdRotate Banner Manager now requires unfiltered html permissions and higher level access for users to create adverts as a way to reduce the risk.

Other changes include a code separation of the plugin in general. Most dashboard only code is now ONLY loaded on the dashboard. This should make the plugin a fair but smaller on the front-end. You can now use webp images in adverts.

To finally bring some consistency in the plugin code I’ve gone through every line of it and made all single and double quotes in a consistent format. This might affect some translations but the included ones are updated to work with it. If you use your own translation make sure all texts are compatible. If you run into issues with this just get in touch and we’ll figure it out!

Also in translations, a bunch of new strings have been added and some that were already there but not labeled correctly have been fixed.

And a whole host of smaller updates and changes to the code, but also the dashboard, to make AdRotate Banner Manager work a lot better. If you run into quirks with functions or how things look, let me know and we’ll quickly fix it.

Changes in version 5.13

  • [new] Upload webp banner images through the media manager
  • [security] Low level users can no longer access the dashboard
  • [security] Low level users can no longer upload html/js/zip files
  • [security] DISALLOW_UNFILTERED_HTML required for Javascript ads
  • [security] DISALLOW_UNFILTERED_HTML required for group wrapper
  • [change] Previews disabled for some Javascript ads
  • [change] Separated most dashboard code from the front-end
  • [change] Updated and merged various functions
  • [update] Enabled/disabled icons now based on generated svg
  • [update] Consistent use of single and double-quotes
  • [i18n] Translations updated
  • [removed] Removed setting to disable dynamic groups
  • [removed] Welcome pointer when first activating the plugin
  • [removed] Lots of unused or outdated code

Download

Grab your update today, available through automatic updates in your dashboard or via direct download through my website. Or if you do not have AdRotate Banner Manager or AdRotate Professional yet, get your copy today through the product pages below.

Leave a Reply