The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.
History

Wed, 14 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta add Image Slider
Averta carousel Slider
Averta coupon Popup
Averta exit Intent Popup
Averta popup Modal
Averta post Slider Carousel
Averta slider And Popup Builder By Depicter
CPEs cpe:2.3:a:averta:add_image_slider:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:carousel_slider:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:coupon_popup:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:exit_intent_popup:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:popup_modal:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:post_slider_carousel:*:*:*:*:*:*:*:*
cpe:2.3:a:averta:slider_and_popup_builder_by_depicter:*:*:*:*:*:*:*:*
Vendors & Products Averta
Averta add Image Slider
Averta carousel Slider
Averta coupon Popup
Averta exit Intent Popup
Averta popup Modal
Averta post Slider Carousel
Averta slider And Popup Builder By Depicter
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 08:45:00 +0000

Type Values Removed Values Added
Description The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-08-14T08:29:44.236Z

Updated: 2024-08-14T13:24:49.540Z

Reserved: 2024-05-01T14:51:50.173Z

Link: CVE-2024-4389

cve-icon Vulnrichment

Updated: 2024-08-14T13:16:38.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-14T09:15:14.007

Modified: 2024-08-14T13:00:37.107

Link: CVE-2024-4389

cve-icon Redhat

No data.