CVE · Medium

CVE-2025-11370 — Depicter — Popup & Slider Builder [depicter] < 4.7.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11370 Depicter — Popup & Slider Builder [depicter] < 4.7.0 Missing Authorization Medium 5.3 < 4.7.0 4.7.0 2026-01-05

CVE-2025-11370

A security flaw exists in the Popup and Slider Builder plugin for WordPress due to a lack of permission checks on certain backend operations. Specifically, an attacker without authentication can manipulate popup display configurations through the 'store' function within the RulesAjaxController class. This vulnerability affects all versions up to 4.0.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.