SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15049

HIGH · CVSS 7.2 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Depicter — Popup & Slider Builder WordPress plugin prior to version 4.8.0 is vulnerable due to inadequate validation of uploaded files, allowing users with editor-level access to upload arbitrary files, including executable PHP scripts, into a web-accessible directory. This flaw can lead to remote code execution, posing a significant risk to site integrity and security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15049
Severity
HIGH
CVSS
7.2
EPSS
0.63%
WordPress

Original NVD Description

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.