CVE-2026-15049
Received Received - Intake

Arbitrary File Upload in Depicter WordPress Plugin

Vulnerability report for CVE-2026-15049, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: WPScan

Description

The Depicter β€” Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
depicter plugin to 4.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Depicter WordPress plugin before version 4.8.0 has a flaw in its file import feature. It does not check the type of files being uploaded, allowing users with editor-level access to upload malicious files like PHP scripts. These files are saved in directories accessible via the web, which can lead to remote code execution by attackers.

Detection Guidance

Check the installed version of the Depicter plugin in WordPress. If it is below 4.8.0, the system is vulnerable. Look for unexpected files in web-accessible directories, especially PHP files uploaded recently.

Impact Analysis

If you use the Depicter plugin before version 4.8.0, an attacker with editor access could upload and execute malicious code on your WordPress site. This could allow them to take control of your website, steal data, or deface it. The vulnerability enables full remote code execution.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. A successful exploit may result in non-compliance, legal penalties, and reputational damage due to compromised sensitive data.

Mitigation Strategies

Update the Depicter plugin to version 4.8.0 or later immediately. Remove any unauthorized files in web-accessible directories. Restrict editor-level user permissions to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15049. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart