Feed/CVE-2026-15049
CVE-2026-15049HIGHCVSS 7.2

CVE-2026-15049

Published Aug 20, 2026·Updated Aug 20, 2026

NVD Description

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free