CVE-2024-4390

MEDIUM

Depicter < 3.0.2 - Authenticated Arbitrary Nonce Generation

Title source: llm
STIX 2.1

Description

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be used to invoke functionality that is protected only by nonce checks.

Scores

CVSS v3 6.5
EPSS 0.0051
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269 CWE-863
Status published
Products (2)
averta/Depicter — Popup & Slider Builder < 3.0.2
depicter/depicter < 3.1.0
Published Jun 20, 2024
Tracked Since Feb 18, 2026