Junglewise Threat Intelligence

CVE-2026-66622: Depicter Slider SQL injection

CVE-2026-66622 · Severity: high · CVSS 7.5 · Published 2026-08-18

Executive brief

Depicter Slider is a WordPress plugin used to create image sliders and galleries on websites. Unauthenticated attackers can exploit a SQL injection flaw to read, modify, or delete the entire WordPress database, including user credentials and customer data, without requiring any login credentials.

Technical details

A SQL injection vulnerability exists in Depicter Slider plugin version 4.8.0 and earlier. The flaw allows unauthenticated attackers to inject arbitrary SQL commands, likely through user-supplied input that is not properly sanitized or parameterized. No authentication is required to exploit this issue, making it accessible over the network. Successful exploitation enables attackers to execute arbitrary database queries to read sensitive data, modify database contents, or drop tables. The vulnerability has been patched in version 4.8.1 and later.

Affected products

  • Penge Zhou Depicter Slider <=4.8.0

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in version 4.8.1
  • 2026-04-12: kev added: Reported by Peng Zhou

References