The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Averta
Averta slider And Popup Builder By Depicter Wordpress Wordpress wordpress |
|
| Vendors & Products |
Averta
Averta slider And Popup Builder By Depicter Wordpress Wordpress wordpress |
Fri, 31 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Depicter <= 4.0.4 - Cross-Site Request Forgery | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-31T08:25:55.580Z
Updated: 2025-10-31T17:51:16.878Z
Reserved: 2025-07-30T18:13:07.830Z
Link: CVE-2025-8383
Updated: 2025-10-31T17:51:12.889Z
Status : Awaiting Analysis
Published: 2025-10-31T09:15:48.573
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-8383
No data.
ReportizFlow