Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation
2024-06-19 14:33
Arkadiusz HydzikStrategic Overview
StatusPatched in 3.1.0
Affected PluginDepicter — Popup & Slider Builder
Affected Version
<= 3.0.2CVSS6.5Medium
CVE
CVE-2024-4390Vulnerability Overview
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be used to invoke functionality that is protected only by nonce checks.
Technical Analysis
REMEDIATION: Update to version 3.1.0, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C