CVE-2024-4389: Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4389?
CVE-2024-4389 is considered a high severity vulnerability due to its potential for arbitrary file uploads by authenticated attackers.
How do I fix CVE-2024-4389?
To fix CVE-2024-4389, update the Depicter Slider & Popup Builder plugin to version 3.1.2 or later.
Who is affected by CVE-2024-4389?
CVE-2024-4389 affects all versions of the Depicter Slider & Popup Builder plugin up to and including 3.1.1.
What type of vulnerability is CVE-2024-4389?
CVE-2024-4389 is a vulnerability due to missing file type validation in the uploadFile function.
Can unauthenticated users exploit CVE-2024-4389?
No, only authenticated attackers with contributor access can exploit CVE-2024-4389.