Description
The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
* (semver)
Timeline
| 2025-10-07: | Vendor Notified |
| 2025-10-30: | Disclosed |
Credits
Dmitrii Ignatyev
References
www.wordfence.com/...-cc51-4367-afe0-11a6abfc0437?source=cve
drive.google.com/...6tX4hHeupjdYsZWZe3gYjqo/view?usp=sharing
plugins.trac.wordpress.org/...cter/trunk/app/routes/ajax.php
plugins.trac.wordpress.org/changeset/3384613/