WordPress Plugin Vulnerabilities
Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
Description
The plugin does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
md. minaruzzaman shovon
Submitter
md. minaruzzaman shovon
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-18 (about 2 days ago)
Added
2026-08-18 (about 1 day ago)
Last Updated
2026-08-18 (about 1 day ago)