header-logo
Suggest Exploit
vendor:
Depicter Plugin
by:
Andrew Long
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Depicter Plugin
Affected Version From: <= 3.6.1
Affected Version To: 3.6.2001
Patch Exists: NO
Related CWE: CVE-2025-2011
CPE: a:wordpress:depicter:3.6.1
Metasploit:
Other Scripts:
Platforms Tested: WordPress
2025

WordPress Depicter Plugin 3.6.1 – SQL Injection

The Slider & Popup Builder by Depicter plugin for WordPress up to version 3.6.1 is vulnerable to SQL Injection through the 's' parameter. Attackers can inject additional SQL queries to extract sensitive data from the database due to lack of proper input validation and escaping.

Mitigation:

Ensure input validation and proper escaping of user-supplied parameters to prevent SQL Injection attacks. Regularly update the Depicter plugin to the latest version.
Source

Exploit-DB raw data: