PT-2025-45086 · WordPress+1 · Slider & Popup Builder+1

·

CVE-2025-11373

·

Published

2025-11-05

·

Updated

2025-11-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Popup and Slider Builder by Depicter versions up to and including 4.0.4
Description The Popup and Slider Builder by Depicter plugin for WordPress has a flaw that allows authenticated attackers with Contributor-level access or higher to upload files to the server. This is due to a lack of capability checks in the depicter-media-upload API endpoint. The uploaded files are limited in type.
Recommendations Versions prior to 4.0.4 should be updated.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11373

Affected Products

Depicter
Slider & Popup Builder