Cross-Site Request Forgery Vulnerability in Depicter Plugin for WordPress
CVE-2025-8383 
4.3MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 31 October 2025
What is CVE-2025-8383?
The Depicter plugin for WordPress is susceptible to Cross-Site Request Forgery due to insufficient nonce validation in the depicter-document-rules-store function. This flaw allows unauthenticated attackers to potentially manipulate document rules by tricking a site administrator into making a request, such as clicking on a deceptive link. It is crucial for site administrators using this plugin to update to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel * <= 4.0.4