Impact
The Depicter plugin for WordPress, prior to version 4.8.0, accepts uploads through its ZIP import feature without checking the MIME type or file extension and fails to remove malformed uploads, allowing users with editor role to place an arbitrary file, including executable PHP, into a publicly accessible directory; this flaw satisfies the file upload weakness CWE‑434 and can lead to remote code execution on the affected site.
Affected Systems
Affected systems are websites running the Depicter — Popup & Slider Builder WordPress plugin of any version earlier than 4.8.0. The vulnerable code is present on all installations that have not applied this update, regardless of the WordPress host or theme.
Risk and Exploitability
The vulnerability scores a moderate CVSS of 7.2, indicating high severity; the EPSS of less than 1% suggests a low probability of exploitation at this time, and the CWE listing indicates a file upload flaw. However, because the issue requires only an authenticated editor‑level user, an attacker with valid credentials or who compromises an editor account can upload a malicious file via the import interface, creating a potential remote code execution vector. The lack of a KEV listing means no publicly known exploits have been reported, but the risk remains significant for sites that allow widespread editor access.
OpenCVE Enrichment