CVE Database /
CVE-2024-4389
CVE · High
CVE-2024-4389 — Depicter — Popup & Slider Builder [depicter] < 3.1.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-4389
|
Depicter — Popup & Slider Builder [depicter] < 3.1.2 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 3.1.2
|
3.1.2 |
2024-08-13 |
—
|
CVE-2024-4389
The Depicter Popup & Slider Builder plugin through version 3.1.1 contains a file upload vulnerability in its uploadFile function that fails to properly validate uploaded file types. Authenticated users with contributor-level permissions or above can exploit this flaw to upload malicious files to the server, potentially enabling remote code execution. The vulnerability was patched in version 3.1.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings