CVE-2025-2011

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

<p><em>Improve users engagement rate or sales by Depicter <strong>Popup</strong>, <strong>Notification Bar</strong>, and Slider builder.</em></p> <p>You can create converting <strong>Popup and Notification Bar</strong>, like <strong>Email subscription popup, Exit intent popup, promotion popup, cart‑abandonment popup, campaign promoting notification bar</strong>. And you can also create engaging WordPress sliders, carousels, and slideshows like <strong>layer slider, video slider, image slider, fullscreen slider, post slider, product slider, WooCommerce slider, testimonial slider, gallery slider and Elementor slider</strong>.</p> <h3>Explore Popup, slider and more Templates</h3> <ul> <li><a href="https://depicter.com/templates/#/popups/all-popups" rel="nofollow ugc">Popup Templates</a></li> <li><a href="https://depicter.com/templates/#/notification-bars/all-notification-bars" rel="nofollow ugc">Notification bar Templates</a></li> <li><a href="https://depicter.com/templates/#/sliders/all-sliders" rel="nofollow ugc">Slider Templates</a></li> <li><a href="https://depicter.com/templates/#/carousels/all-carousels" rel="nofollow ugc">Carousel Templates</a></li> <li><a href="https://depicter.com/templates/#/hero-sections/all-hero-sections" rel="nofollow ugc">Hero Section Templates</a></li> </ul> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/YTf6kFyn52A?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Create popups, notification bars, sliders, and carousels with an intuitive visual builder</h3> <p>Depicter provides a flexible way to design and display interactive elements on your WordPress site. You can create popups, sliding banners, hero sections, carousels, and other visual components without writing code.</p> <h3>Key Features</h3> <ul> <li><strong>Unlimited items</strong> — Create as many popups, notification bars, sliders, and carousels as needed.</li> <li><strong>Template library</strong> — Start quickly with a wide collection of pre-designed layouts for various use cases.</li> <li><strong>AI tools</strong> — Generate slider layouts or content using built-in AI features to speed up your workflow.</li> <li><strong>Form builder</strong> — Add built-in forms to collect email, name, phone number, and other information.</li> <li><strong>Performance-friendly output</strong> — Uses WebP, adaptive images, lazy loading, and optimized asset delivery.</li> <li><strong>Visual editing</strong> — Design content through a simple, responsive editor supporting animations, effects, and custom fonts.</li> </ul> <h3><a href="https://depicter.com/popup" rel="nofollow ugc">Popup</a> and <a href="https://depicter.com/notification-bar" rel="nofollow ugc">Notification Bar</a> Features</h3> <ul> <li><strong>Variety of <a href="https://depicter.com/templates/#/popups/all-popups" rel="nofollow ugc">popup templates</a> and <a href="https://depicter.com/templates/#/notification-bars/all-notification-bars" rel="nofollow ugc">notification bar templates</a></strong></li> <li>Configure display conditions based on pages visited, device type, referrer, location, cookies, or user behavior.</li> <li>Define scheduling rules for when a popup or notification bar should appear or expire.</li> <li>Choose from multiple triggers: exit intent, scroll depth, time on page, inactivity, or user interactions.</li> <li>Control reopening behavior: once per visitor, every visit, or after a specific delay.</li> <li>Create multi-step popups for more complex interactions.</li> <li>Customize mobile responsiveness and add animations or visual effects.</li> </ul> <h3><a href="https://depicter.com/slider" rel="nofollow ugc">Slider</a> and <a href="https://depicter.net/carousel/" rel="nofollow ugc">Carousel</a> Features</h3> <ul> <li>Create fully responsive sliders and carousels that adapt to all device sizes.</li> <li>Add animations, transitions, and parallax effects to enhance visuals.</li> <li>Use arrows, bullets, timers, and swipe navigation for a more interactive experience.</li> <li>Populate sliders with dynamic content including posts, WooCommerce products, or custom post types.</li> <li>Compatible with major page builders: Elementor, Divi, Beaver Builder, Oxygen, and the WordPress block editor.</li> <li>Add video backgrounds from YouTube or Vimeo.</li> <li>Set scheduling rules to control when sliders or carousels appear on the site.</li> </ul> <p><strong>How to create a WordPress slider with Depicter</strong></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/yi_NjXKlvmg?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p><strong>Create a WordPress slider with AI in seconds</strong></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/kdR9Jw0yWjU?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Use of 3rd Party Services</h3> <p>To improve the user experience, Depicter may use the following 3rd party services if the required feature is enabled:</p> <ul> <li>Google Places and Recaptcha are used to display location, reviews and recaptcha. Google&#8217;s <a href="https://policies.google.com/terms" rel="nofollow ugc">TOS</a> and <a href="https://policies.google.com/privacy" rel="nofollow ugc">Privacy Policy</a></li> <li>Some Depicter features and services required to contact depicter website. These features and services are not used for tracking unless explicitly mentioned, requiring your approval and manual opt-in. Learn more in our <a href="https://depicter.com/terms-and-conditions/" rel="nofollow ugc">TOS</a>.</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
2.06M