Executive brief
Depicter is a WordPress plugin for building popups and sliders. The plugin fails to validate uploaded files in its import feature, allowing editors to upload and execute arbitrary PHP code on the web server, leading to complete site compromise and potential data theft or malware installation.
Technical details
The vulnerability is an arbitrary file upload flaw in the ZIP import handler (depicter-document-import-file-zip AJAX action). The plugin checks only the multipart Content-Type header (application/zip) without validating the actual file content; when a non-ZIP payload is uploaded, PHP's ZipArchive throws an uncaught error that skips the cleanup routine, leaving the attacker-supplied file persisted to disk with a .php extension in wp-content/uploads/depicter/. An authenticated user with editor-level privileges can exploit this to write executable PHP code, achieving remote code execution if the server executes PHP in the uploads directory (the default configuration). The vulnerability was fixed in version 4.8.0 by adding proper file type validation and handling malformed uploads.
Affected products
- Depicter Popup & Slider Builder before 4.8.0
Timeline
- 2026-08-18: disclosed
- 2026-08-20: patched: Fixed in version 4.8.0
- 2026-08-20: advisory