CVE Database /
CVE-2025-68500
CVE · Medium
CVE-2025-68500 — Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons [bdthemes-prime-slider-lite] < 4.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-68500
|
Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons [bdthemes-prime-slider-lite] < 4.1.0 |
Server-Side Request Forgery (SSRF) |
Medium
4.9
|
< 4.1.0
|
4.1.0 |
2025-12-13 |
—
|
CVE-2025-68500
The Prime Slider – Addons for Elementor WordPress plugin has a security flaw that allows malicious users with at least Subscriber privileges to initiate unauthorized external network connections from the affected website, potentially exposing sensitive data or disrupting internal systems. This vulnerability affects all versions of the plugin up to and including 4.0.10.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings