WordPress · The Depicter Slider · CVE-2023-6493
**Name of the Vulnerable Software and Affected Versions**
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress versions up to, and including, 2.0.6
**Description**
The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the `save` function. This allows unauthenticated attackers to modify the plugin's settings by tricking a site administrator into performing an action, such as clicking on a link.
**Recommendations**
For versions up to, and including, 2.0.6, update to a version that includes the fix for the missing or incorrect nonce validation on the `save` function.
As a temporary workaround, consider restricting access to the plugin's settings to minimize the risk of exploitation.