Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Qué hace este plugin
- Slug:
bdthemes-prime-slider-lite
- Autor: bdthemes
- 100000+ instalaciones activas
- 90/100 calificación (81 reseñas en wordpress.org)
- 6271960 descargas totales
- En WordPress.org desde 2019-10-07
content sliderelementor addonhero sliderimage slidervideo slider
Estado de mantenimiento
- Última actualización: 2026-07-14 12:57pm GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.4.0+
Vulnerabilidades conocidas
17 CVEs conocidos registrados para Bdthemes Prime Slider Lite.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-14277
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 |
Falsificación de petición del lado del servidor (SSRF) |
Media
4,3
|
< 4.1.0
|
4.1.0 |
2025-12-17 |
—
|
|
CVE-2025-68500
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 |
Falsificación de petición del lado del servidor (SSRF) |
Media
4,9
|
< 4.1.0
|
4.1.0 |
2025-12-13 |
—
|
|
CVE-2024-12043
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.16.6
|
3.16.6 |
2025-01-22 |
—
|
|
CVE-2024-8442
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.15.19 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.15.19
|
3.15.19 |
2024-11-06 |
—
|
|
CVE-2024-5640
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.14.8
|
3.14.8 |
2024-06-06 |
—
|
|
CVE-2024-3997
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.14.2
|
3.14.2 |
2024-05-22 |
—
|
|
CVE-2024-4339
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.14.4
|
3.14.4 |
2024-05-07 |
—
|
|
CVE-2024-1730
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.14.1
|
3.14.1 |
2024-04-19 |
—
|
CVE-2025-14277
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-68500
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-12043
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-8442
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5640
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3997
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4339
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-1730
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images from URLs, and html tags used in widgets in all versions up to, and including, 3.14.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 12 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-32681
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Falta de control de autorización |
Alta
8,8
|
< 3.13.3
|
3.13.3 |
2024-04-17 |
—
|
|
CVE-2024-32682
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Falta de control de autorización |
Alta
8,8
|
< 3.13.3
|
3.13.3 |
2024-04-17 |
—
|
|
CVE-2024-30186
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.13.2
|
3.13.2 |
2024-03-25 |
—
|
|
CVE-2024-1508
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.13.3
|
3.13.3 |
2024-03-12 |
—
|
|
CVE-2024-1507
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.13.4
|
3.13.4 |
2024-03-12 |
—
|
|
CVE-2024-1506
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.13.2
|
3.13.2 |
2024-03-06 |
—
|
|
CVE-2024-24883
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.11.11 |
Falta de control de autorización |
Media
4,3
|
< 3.11.11
|
3.11.11 |
2024-02-05 |
—
|
|
CVE-2023-33999
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.8.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 3.8.3
|
3.8.3 |
2023-07-18 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
Falta de control de autorización |
Media
6,3
|
< 2.7.0
|
2.7.0 |
2022-03-04 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
— |
Desconocido
|
< 2.7.0
|
2.7.0 |
2022-02-28 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
— |
Desconocido
|
< 2.7.0
|
2.7.0 |
2022-02-28 |
—
|
|
CVE-2026-4341
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.11 |
— |
Desconocido
|
< 4.1.11
|
4.1.11 |
0000-00-00 |
—
|
CVE-2024-32681
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dci_sdk_insights, dci_sdk_dismiss_notice, and rc_sdk_dismiss_notice functions in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-32682
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss() function in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-30186
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.2).
Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.2.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1508
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3).
RandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1507
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3).
Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1506
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-24883
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.11.11).
Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.11.11.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-33999
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.8.3).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.8.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
El SDK de Freemius, utilizado por cientos de desarrolladores de plugins y temas de WordPress, estaba expuesto a Cross-Site Request Forgery (CSRF) y revelación de información debido a la falta de comprobaciones de capacidad y protección con nonce en las funciones _get_debug_log, _get_db_option y _set_db_option en versiones hasta y inclusive 2.4.2. Cualquier plugin o tema de WordPress que ejecute una versión de Freemius menor a 2.4.3 es vulnerable.
Traducción automática del texto original de la fuente.
Ver original
Fuente:
Wordfence
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
Sensitive Information Disclosure vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2026-4341
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget setting using `echo` without any escaping function. The setting value is stored in `_elementor_data` post meta via `update_post_meta`. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas