CVE-2024-4390: Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be used to invoke functionality that is protected only by nonce checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Depicter Slider and Carousel Slider by Depicter pluginto a version that resolves this vulnerability.Fixed in 3.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4390?
CVE-2024-4390 has a medium severity rating as it allows authenticated attackers to generate valid nonces.
How do I fix CVE-2024-4390?
To fix CVE-2024-4390, update the Depicter plugin to version 3.1.0 or higher.
Who is affected by CVE-2024-4390?
CVE-2024-4390 affects all versions of the Depicter plugin for WordPress up to and including 3.0.2.
What types of attackers can exploit CVE-2024-4390?
Only authenticated attackers with contributor access or higher can exploit CVE-2024-4390.
What does CVE-2024-4390 allow an attacker to do?
CVE-2024-4390 allows an authenticated attacker to generate a valid nonce for any WordPress action.