CVE-2026-66622: WordPress Depicter Slider plugin <= 4.8.0 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Affected Software
1 affected component
wordpress/Depicter Slider<=4.8.0
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites running Depicter Slider version 4.8.0 or earlier are affected. The vulnerability is remotely reachable and requires no authentication or user interaction.
2
What does an attacker need to exploit this issue?
An attacker must be able to reach the affected site over the network. Exploitation has high attack complexity, but it does not require privileges or interaction from a victim.
3
What is the potential impact?
Successful exploitation can expose highly confidential data and can have an impact beyond the vulnerable plugin's security scope. The stated availability impact is low, and no integrity impact is listed.