The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44022 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Averta
Averta add Image Slider Averta carousel Slider Averta coupon Popup Averta exit Intent Popup Averta popup Modal Averta post Slider Carousel Averta slider And Popup Builder By Depicter |
|
| CPEs | cpe:2.3:a:averta:add_image_slider:*:*:*:*:*:*:*:* cpe:2.3:a:averta:carousel_slider:*:*:*:*:*:*:*:* cpe:2.3:a:averta:coupon_popup:*:*:*:*:*:*:*:* cpe:2.3:a:averta:exit_intent_popup:*:*:*:*:*:*:*:* cpe:2.3:a:averta:popup_modal:*:*:*:*:*:*:*:* cpe:2.3:a:averta:post_slider_carousel:*:*:*:*:*:*:*:* cpe:2.3:a:averta:slider_and_popup_builder_by_depicter:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Averta
Averta add Image Slider Averta carousel Slider Averta coupon Popup Averta exit Intent Popup Averta popup Modal Averta post Slider Carousel Averta slider And Popup Builder By Depicter |
|
| Metrics |
ssvc
|
Wed, 14 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
| Title | Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:03:50.955Z
Reserved: 2024-05-01T14:51:50.173Z
Link: CVE-2024-4389
Updated: 2024-08-14T13:16:38.217Z
Status : Deferred
Published: 2024-08-14T09:15:14.007
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-4389
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD