PT-2025-45086 · WordPress+1 · Slider & Popup Builder+1

Rafshanzani Suhada

·

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-11373

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Popup and Slider Builder by Depicter versions up to and including 4.0.4
Description The Popup and Slider Builder by Depicter plugin for WordPress has a flaw that allows authenticated attackers with Contributor-level access or higher to upload files to the server. This is due to a lack of capability checks in the depicter-media-upload API endpoint. The uploaded files are limited in type.
Recommendations Versions prior to 4.0.4 should be updated.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11373

Affected Products

Depicter
Slider & Popup Builder