CVE-2024-4389: Averta Add Image Slider

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Affected products

  • Averta Add Image Slider: up to and including 3.11
  • Averta Carousel Slider: up to and including 3.1.1
  • Averta Coupon Popup: up to and including 3.1..1
  • Averta Depicter — Popup & Slider Builder: up to and including 3.1.1
  • Averta Exit Intent Popup: up to and including 3.1.1
  • Averta Popup Modal: up to and including 3.1.1
  • Averta Post Slider Carousel: up to and including 3.1.1
  • Averta Slider And Popup Builder By Depicter: up to and including 3.11

Published 2024-08-14. Last modified 2026-06-17.