PatchSiren cyber security CVE debrief
CVE-2026-15049 Depicter CVE debrief
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution. This vulnerability affects WordPress installations using the Depicter plugin, potentially allowing attackers to gain unauthorized access or control. Administrators and users of the Depicter — Popup & Slider Builder WordPress plugin should be aware of this vulnerability and take immediate action to address it.
- Vendor
- Depicter
- Product
- Popup & Slider Builder
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the Depicter — Popup & Slider Builder WordPress plugin, as well as security teams responsible for monitoring and patching vulnerabilities in WordPress installations, should be aware of this vulnerability and take immediate action to address it. Additionally, operators of WordPress-based platforms and security teams responsible for vulnerability management should also be aware of this issue and review their deployments for potential exposure. This vulnerability may impact the security of the affected systems and potentially allow attackers to gain unauthorized access or control. Therefore, it is essential to prioritize patching and mitigation efforts to prevent potential exploitation. Security teams should also review their monitoring and detection capabilities to ensure they can identify potential exploitation attempts. Furthermore, asset inventory and vulnerability management processes should be updated to reflect the potential risks associated with this vulnerability. Compensating controls, such as web application firewalls, may also be necessary to mitigate the risk of exploitation until a patch is applied.
Technical summary
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory. This can lead to remote code execution, potentially allowing attackers to gain control of the affected system. The vulnerability is caused by a lack of file type validation and inadequate upload handling, making it essential to prioritize patching and mitigation efforts to prevent potential exploitation.
Defensive priority
High-priority defensive actions are required to address this vulnerability, as it allows for remote code execution.
Recommended defensive actions
- Inventory and verify installed plugin versions
- Restrict upload access to trusted users
- Implement web application firewall rules
- Monitor for suspicious file uploads and system changes
- Apply vendor patch or upgrade to version 4.8.0 or later
Evidence notes
Evidence from the NVD and WPScan suggests that the Depicter plugin is vulnerable to arbitrary file uploads, which can lead to remote code execution. However, details on affected versions and scope are limited. Further verification is needed to confirm the extent of the vulnerability and to identify potential mitigations. The vulnerability allows users with editor-level access to write an arbitrary file, including executable PHP, into a web-accessible directory. This can lead to remote code execution, potentially allowing attackers to gain control of the affected system. To verify the vulnerability, defenders should review the plugin's import feature and check for any suspicious file uploads or system changes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15049 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15049
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15049 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15049
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/c32e6a11-98f2-48e8-be64-f0c1966ddc18/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.