Segurium Research Advisories depicter

Depicter 4.8.0 and earlier: SQL injection

high SQL injection

Depicter 4.8.1 rewrites the lead export query. Form field names from public submissions went straight into a raw MAX(IF()) SQL fragment, and sort parameters reached ORDER BY with no check. Update sites on 4.8.0 or earlier.

Plugin
Depicter depicter
Affected versions
4.8.0 and earlier
Fixed in
4.8.1
Class
SQL injection
Severity
high Segurium Research assessment. No CVSS score published yet.
CVE
None assigned at the time of writing
Installs
80,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.