Depicter — Popup & Slider Builder < 4.8.0 - Authenticated (Editor+) Arbitrary File Upload
high
The Depicter — Popup & Slider Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to 4.8.0. This is due to missing file type validation. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files on the affected site's server, whi...
- CVSS:
- 7.2
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 21, 2026
CVE-2026-15049 on NVD →
Depicter — Popup & Slider Builder <= 4.8.0 - Unauthenticated SQL Injection
high
The Depicter — Popup & Slider Builder plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.8.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.5
- Affected:
- up to 4.8.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-66622 on NVD →
Depicter — Popup & Slider Builder [depicter] <= 4.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in averta Depicter Slider depicter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through <= 4.0.4.
- Affected:
- up to 4.0.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68558 on NVD →
Depicter — Popup & Slider Builder [depicter] < 4.7.0
unknown
[en] The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'store' function of the RulesAjaxController class in...
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.0
- Disclosed:
- Jan 6, 2026
CVE-2025-11370 on NVD →
Depicter <= 4.0.7 - Missing Authorization to Unauthenticated Display Rule Updates
medium
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'store' function of the RulesAjaxController class in all...
- CVSS:
- 5.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.7.0
- Disclosed:
- Jan 5, 2026
CVE-2025-11370 on NVD →
Depicter Slider <= 4.0.4 - Missing Authorization
medium
The Depicter — Popup & Slider Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Jan 5, 2026
CVE-2025-68558 on NVD →
Depicter — Popup & Slider Builder [depicter] < 4.0.5
unknown
[en] The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability checks in the "depicter-media-upload" AJAX route in all versions up to, and...
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.5
- Disclosed:
- Nov 5, 2025
CVE-2025-11373 on NVD →
Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload
medium
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability checks in the "depicter-media-upload" AJAX route in all versions up to, and inclu...
- CVSS:
- 4.3
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Nov 4, 2025
CVE-2025-11373 on NVD →
Depicter <= 4.0.4 - Cross-Site Request Forgery
medium
The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Oct 30, 2025
CVE-2025-8383 on NVD →
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
high
The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unaut...
- CVSS:
- 7.5
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- May 5, 2025
CVE-2025-2011 on NVD →
Depicter — Popup & Slider Builder [depicter] < 1.9.1
unknown
[en] Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Dec 13, 2024
CVE-2022-47176 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.2.2
unknown
[en] The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level...
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Dec 6, 2024
CVE-2024-4633 on NVD →
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting
medium
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permi...
- CVSS:
- 6.4
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.2
- Disclosed:
- Dec 5, 2024
CVE-2024-4633 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.5.0
unknown
[en] Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Depicter Slider: from n/a through 3.2.2.
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Nov 1, 2024
CVE-2024-47359 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.5.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.2.2.
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Oct 5, 2024
CVE-2024-47381 on NVD →
Depicter Slider <= 3.2.2 - Missing Authorization
medium
The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.2. This makes it possible for...
- CVSS:
- 5.3
- Affected:
- up to 3.2.2
- Fixed in:
- 3.5.0
- Disclosed:
- Sep 30, 2024
CVE-2024-47359 on NVD →
Depicter Slider <= 3.2.2 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output esca...
- CVSS:
- 4.4
- Affected:
- up to 3.2.2
- Fixed in:
- 3.5.0
- Disclosed:
- Sep 30, 2024
CVE-2024-47381 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.1.2
unknown
[en] The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitr...
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Aug 14, 2024
CVE-2024-4389 on NVD →
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload
high
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary f...
- CVSS:
- 8.8
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Aug 13, 2024
CVE-2024-4389 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.2.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.1.2.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43161 on NVD →
Depicter Slider <= 3.1.2 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output esca...
- CVSS:
- 4.4
- Affected:
- up to 3.1.2
- Fixed in:
- 3.2.0
- Disclosed:
- Aug 7, 2024
CVE-2024-43161 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.0.2.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jul 22, 2024
CVE-2024-37414 on NVD →
Depicter Slider <= 3.0.2 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 4.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.1.0
- Disclosed:
- Jun 28, 2024
CVE-2024-37414 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.1.0
unknown
[en] The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be u...
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jun 20, 2024
CVE-2024-4390 on NVD →
Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation
medium
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be used t...
- CVSS:
- 6.5
- Affected:
- up to 3.0.2
- Fixed in:
- 3.1.0
- Disclosed:
- Jun 19, 2024
CVE-2024-4390 on NVD →
Depicter — Popup & Slider Builder [depicter] < 2.0.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Averta Depicter Slider.This issue affects Depicter Slider: from n/a through 2.0.6.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Mar 16, 2024
CVE-2023-51491 on NVD →
Depicter — Popup & Slider Builder [depicter] < 2.0.7
unknown
[en] The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers t...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 5, 2024
CVE-2023-6493 on NVD →
Depicter Slider – Responsive Image Slider, Video Slider & Post Slider <= 2.0.6 - Cross-Site Request Forgery via save
medium
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to mod...
- CVSS:
- 4.3
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 4, 2024
CVE-2023-6493 on NVD →
Depicter Slider <= 1.9.0 - Missing Authorization on 'make' function
medium
The Depicter Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multiple functions in versions up to, and including, 1.9.0. This makes it possible for authenticated attackers, with contributor-level access and above, to create, publish, and edit sliders
- CVSS:
- 5.4
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Apr 28, 2023
CVE-2022-47176 on NVD →
Depicter — Popup & Slider Builder [depicter] < 3.6.2
unknown
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
CVE-2025-2011 on NVD →