The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Project Subscriptions

Vendors Products
Slider And Popup Builder By Depicter Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 22 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta slider And Popup Builder By Depicter
Wordpress
Wordpress wordpress
Vendors & Products Averta
Averta slider And Popup Builder By Depicter
Wordpress
Wordpress wordpress

Fri, 31 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Depicter <= 4.0.4 - Cross-Site Request Forgery
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-12-22T17:22:32.719Z

Reserved: 2025-07-30T18:13:07.830Z

Link: CVE-2025-8383

cve-icon Vulnrichment

Updated: 2025-10-31T17:51:12.889Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-31T09:15:48.573

Modified: 2025-12-19T16:16:00.680

Link: CVE-2025-8383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-03T10:45:00Z

Weaknesses