CVE-2026-15049
Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
| Vendor | unknown |
| Product | depicter — popup & slider builder |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown depicter — popup & slider builder
Be the first to know when new unknown vulnerabilities affecting unknown depicter — popup & slider builder are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Depicter — Popup & Slider Builder
0 < 4.8.0
References
Credits
md. minaruzzaman shovon WPScan