CVE-2025-11373: Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability checks in the "depicter-media-upload" AJAX route in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files on the affected site's server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11373?
The severity of CVE-2025-11373 is considered high due to its potential to allow unauthorized arbitrary file uploads.
How do I fix CVE-2025-11373?
To fix CVE-2025-11373, update the Depicter Popup and Slider Builder plugin to version 4.0.5 or higher, which addresses the vulnerability.
Which versions of Depicter Popup and Slider Builder are affected by CVE-2025-11373?
CVE-2025-11373 affects all versions of the Depicter Popup and Slider Builder plugin up to and including version 4.0.4.
What type of vulnerability is CVE-2025-11373?
CVE-2025-11373 is an arbitrary file upload vulnerability due to missing capability checks in the AJAX functionality of the plugin.
Who is the vendor for the vulnerable software identified in CVE-2025-11373?
The vendor for the vulnerable software identified in CVE-2025-11373 is Depicter.