WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Bdthemes Prime Slider Lite?

Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.

Qué hace este plugin

  • Slug: bdthemes-prime-slider-lite
  • Autor: bdthemes
  • 100000+ instalaciones activas
  • 90/100 calificación (81 reseñas en wordpress.org)
  • 6271960 descargas totales
  • En WordPress.org desde 2019-10-07

content sliderelementor addonhero sliderimage slidervideo slider

Estado de mantenimiento

  • Última actualización: 2026-07-14 12:57pm GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 7.4.0+

Vulnerabilidades conocidas

17 CVEs conocidos registrados para Bdthemes Prime Slider Lite.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-14277 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 Falsificación de petición del lado del servidor (SSRF) Media 4,3 < 4.1.0 4.1.0 2025-12-17
CVE-2025-68500 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 Falsificación de petición del lado del servidor (SSRF) Media 4,9 < 4.1.0 4.1.0 2025-12-13
CVE-2024-12043 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.16.6 3.16.6 2025-01-22
CVE-2024-8442 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.15.19 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.15.19 3.15.19 2024-11-06
CVE-2024-5640 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.14.8 3.14.8 2024-06-06
CVE-2024-3997 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.14.2 3.14.2 2024-05-22
CVE-2024-4339 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.14.4 3.14.4 2024-05-07
CVE-2024-1730 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.14.1 3.14.1 2024-04-19

CVE-2025-14277

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-68500

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-12043

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-8442

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5640

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3997

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4339

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1730

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images from URLs, and html tags used in widgets in all versions up to, and including, 3.14.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 12 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-32681 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Falta de control de autorización Alta 8,8 < 3.13.3 3.13.3 2024-04-17
CVE-2024-32682 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Falta de control de autorización Alta 8,8 < 3.13.3 3.13.3 2024-04-17
CVE-2024-30186 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.13.2 3.13.2 2024-03-25
CVE-2024-1508 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.13.3 3.13.3 2024-03-12
CVE-2024-1507 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.13.4 3.13.4 2024-03-12
CVE-2024-1506 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.13.2 3.13.2 2024-03-06
CVE-2024-24883 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.11.11 Falta de control de autorización Media 4,3 < 3.11.11 3.11.11 2024-02-05
CVE-2023-33999 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.8.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 3.8.3 3.8.3 2023-07-18
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Falta de control de autorización Media 6,3 < 2.7.0 2.7.0 2022-03-04
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Desconocido < 2.7.0 2.7.0 2022-02-28
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Desconocido < 2.7.0 2.7.0 2022-02-28
CVE-2026-4341 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.11 Desconocido < 4.1.11 4.1.11 0000-00-00

CVE-2024-32681

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dci_sdk_insights, dci_sdk_dismiss_notice, and rc_sdk_dismiss_notice functions in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-32682

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss() function in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-30186

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.2). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.2. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1508

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3). RandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1507

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3). Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1506

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-24883

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.11.11). Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.11.11. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-33999

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.8.3). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.8.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

El SDK de Freemius, utilizado por cientos de desarrolladores de plugins y temas de WordPress, estaba expuesto a Cross-Site Request Forgery (CSRF) y revelación de información debido a la falta de comprobaciones de capacidad y protección con nonce en las funciones _get_debug_log, _get_db_option y _set_db_option en versiones hasta y inclusive 2.4.2. Cualquier plugin o tema de WordPress que ejecute una versión de Freemius menor a 2.4.3 es vulnerable.

Traducción automática del texto original de la fuente. Ver original

Fuente: Wordfence

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

Sensitive Information Disclosure vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2026-4341

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget setting using `echo` without any escaping function. The setting value is stored in `_elementor_data` post meta via `update_post_meta`. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.