WordPress Plugin Vulnerabilities

Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import

Description

The plugin does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

Proof of Concept

Affects Plugins

Fixed in 4.8.0

References

Miscellaneous

Original Researcher
md. minaruzzaman shovon
Submitter
md. minaruzzaman shovon
Verified
Yes

Timeline

Publicly Published
2026-08-18 (about 2 days ago)
Added
2026-08-18 (about 1 day ago)
Last Updated
2026-08-18 (about 1 day ago)

Other