Description

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.

INFO

Published Date :

2024-08-14T08:29:44.236Z

Last Modified :

2026-04-08T17:03:50.955Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-4389 vulnerability.

Vendors Products
Averta
  • Add Image Slider
  • Carousel Slider
  • Coupon Popup
  • Exit Intent Popup
  • Popup Modal
  • Post Slider Carousel
  • Slider And Popup Builder By Depicter

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact