Cross-Site Request Forgery Vulnerability in Depicter Plugin for WordPress
CVE-2025-8383

4.3MEDIUM

What is CVE-2025-8383?

The Depicter plugin for WordPress is susceptible to Cross-Site Request Forgery due to insufficient nonce validation in the depicter-document-rules-store function. This flaw allows unauthenticated attackers to potentially manipulate document rules by tricking a site administrator into making a request, such as clicking on a deceptive link. It is crucial for site administrators using this plugin to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel * <= 4.0.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.