Arbitrary File Upload Vulnerability in Depicter Slider and Carousel Slider for WordPress
CVE-2024-4389

8.8HIGH

Summary

The Depicter Slider and Carousel plugin for WordPress is exposed to a significant vulnerability that permits arbitrary file uploads. This results from inadequate file type validation within the uploadFile function. Attackers with contributor or higher access can exploit this flaw to upload harmful files to the affected WordPress site's server. Such a vulnerability increases the risk of remote code execution, potentially compromising website integrity and security. It is essential for users operating versions up to and including 3.1.1 to take immediate action to mitigate this risk.

Affected Version(s)

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel * <= 3.1.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Hydzik
.