What the vulnerability does
01Description
Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.
Explanation of Vulnerability in Simple Terms
02Summary
Depicter Slider and Popup by Averta versions up to 1.9.0 lack proper authorization checks, allowing authenticated users with low privileges to access sensitive information they should not be able to view. An attacker with a basic user account can read data that is restricted to higher-privilege roles. Update to a version newer than 1.9.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data restricted to higher-privilege users by making direct requests.
Potential impact on your site
04Site Impact
Unauthorized users can access confidential information; review user permissions and audit access logs.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the site.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated