
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11370 is a Missing Authorization vulnerability in the "Popup and Slider Builder by Depicter" WordPress plugin (developed by Averta) that allows unauthenticated attackers to modify pop-up display settings. The flaw affects all versions up to and including 4.0.7 and was disclosed on January 5–6, 2026, with Wordfence as the assigning CNA. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the store function of the RulesAjaxController class. As shown in the plugin's route definitions, the depicter-document-rules-store AJAX endpoint is registered without any userCan middleware or CSRF protection, unlike most other sensitive endpoints in the plugin which enforce userCan:edit_depicter and CSRF token validation (GitHub PoC - ajax.php). An unauthenticated attacker can send a crafted HTTP POST request to the WordPress AJAX handler (wp-admin/admin-ajax.php) with the action depicter-document-rules-store, supplying a document ID and arbitrary JSON content to overwrite the display rules (conditions controlling when/where popups appear) for any Depicter document (GitHub PoC - RulesAjaxController.php). No authentication or special preconditions are required beyond network access to the WordPress site.
Successful exploitation allows any unauthenticated remote attacker to arbitrarily modify the display rules and conditions for Depicter popups and sliders on the affected WordPress site. The integrity impact is limited — attackers cannot read sensitive data or crash the site — but they could manipulate popup behavior (e.g., forcing popups to always display, suppressing them, or altering targeting conditions), which could be leveraged for social engineering, suppressing security notices, or disrupting marketing/lead-generation workflows. There is no confidentiality or availability impact, and lateral movement potential is minimal (Wordfence).
A public proof-of-concept reproduction repository was published by researcher nguy3nB4oo11 on GitHub alongside the CVE disclosure, demonstrating the vulnerable code paths (GitHub PoC - ajax.php). The EPSS score is approximately 0.048% (very low), and there is no evidence of active in-the-wild exploitation or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of reporting. No threat actor attribution has been identified (Red Hat CVE).
/wp-content/plugins/depicter/) or using tools like WPScan.depicter-document-rules-show GET endpoint (also lacking strict auth in some versions) to enumerate document IDs.https://target-site.com/wp-admin/admin-ajax.php with the body parameters action=depicter-document-rules-store, ID=<target_document_id>, and content=<arbitrary_JSON_rules>.store function in RulesAjaxController will accept and persist the supplied rules via \Depicter::metaRepository()->update($id, 'rules', $content).depicter-document-rules-show endpoint for the affected document ID (GitHub PoC - RulesAjaxController.php, GitHub PoC - ajax.php)./wp-admin/admin-ajax.php with action=depicter-document-rules-store originating from unauthenticated (no session cookie) or unknown IP addresses.admin-ajax.php with the depicter-document-rules-store action parameter from IPs not associated with site administrators; repeated requests with varying ID values may indicate enumeration.rules field) in the WordPress database (wp_postmeta or Depicter's custom meta tables), particularly if timestamps do not align with known administrator activity.The vulnerability was patched in the plugin changeset 3428118, which adds proper authorization middleware to the depicter-document-rules-store route (WordPress Trac). Site administrators should update the Depicter plugin to version 4.0.8 or later immediately via the WordPress plugin dashboard. As a temporary workaround, sites unable to update immediately can consider disabling the plugin or restricting access to wp-admin/admin-ajax.php for unauthenticated users via web server rules, though this may impact other plugin functionality.
Wordfence, which assigned the CVE, published the vulnerability details in their threat intelligence database and the Sucuri blog included it in their January 2026 vulnerability patch roundup (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond the initial disclosure and PoC publication has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."