The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
History

Thu, 20 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
Title Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-20T09:40:17.920Z

Reserved: 2026-07-08T12:51:17.758Z

Link: CVE-2026-15049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T06:16:49.710

Modified: 2026-08-20T06:16:49.710

Link: CVE-2026-15049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.