SecAlerts
d

depicter

Security Risk Profile

30
/100
low

Security Risk Score

Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 16, 2024 to present

9
Total CVEs
4
Critical+High
1
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
30/100
low
⚠️ 1 Active Exploits

Severity Distribution

Critical
1
High
3
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
CSRF
3
2
XSS
2
3
SQL Injection
1
4
Malicious File Upload
1

Most Affected Products

1. Depicter Depicter Wordpress4
2. Depicter Slider & Popup Builder3
3. Depicter Popup and Slider Builder1
4. Depicter Depicter plugin for WordPress1
5. averta Depicter Slider1

Recent Vulnerabilities

See more →
CVE-2025-11373
CVSS 4.3medium

Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload

Nov 5, 2025🔧 No Patch
CVE-2025-8383
CVSS 4.3medium

Depicter <= 4.0.4 - Cross-Site Request Forgery

Oct 31, 2025🔧 No Patch
CVE-2025-2011
CVSS 7.5high

Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter

May 6, 2025⚠ Exploited🔧 No Patch
CVE-2024-4633
CVSS 6.4medium

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting

Dec 6, 2024🔧 No Patch
CVE-2024-47359
CVSS 9.8critical

WordPress Depicter plugin <= 3.2.2 - Broken Access Control vulnerability

Nov 1, 2024
CVE-2024-4389
CVSS 8.8high

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload

Aug 14, 2024🔧 No Patch
CVE-2024-37414
CVSS 5.9medium

WordPress Depicter Slider plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnerability

Jul 22, 2024
CVE-2024-4390
CVSS 6.5medium

Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation

Jun 20, 2024🔧 No Patch
CVE-2023-51491
CVSS 8.8high

WordPress Depicter Slider plugin <= 2.0.6 - Cross Site Request Forgery (CSRF) vulnerability

Mar 16, 2024

Monitor depicter in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.