First published: Wed Aug 14 2024(Updated: )
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Depicter Slider & Popup Builder | <=3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4389 is considered a high severity vulnerability due to its potential for arbitrary file uploads by authenticated attackers.
To fix CVE-2024-4389, update the Depicter Slider & Popup Builder plugin to version 3.1.2 or later.
CVE-2024-4389 affects all versions of the Depicter Slider & Popup Builder plugin up to and including 3.1.1.
CVE-2024-4389 is a vulnerability due to missing file type validation in the uploadFile function.
No, only authenticated attackers with contributor access can exploit CVE-2024-4389.