WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Bdthemes Prime Slider Lite safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Bdthemes Prime Slider Lite WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: bdthemes-prime-slider-lite

Maintenance status

Known vulnerabilities

17 known CVEs on file for Bdthemes Prime Slider Lite.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14277 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 Server-Side Request Forgery (SSRF) Medium 4.3 < 4.1.0 4.1.0 2025-12-17
CVE-2025-68500 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 Server-Side Request Forgery (SSRF) Medium 4.9 < 4.1.0 4.1.0 2025-12-13
CVE-2024-12043 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.16.6 3.16.6 2025-01-22
CVE-2024-8442 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.15.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.15.19 3.15.19 2024-11-06
CVE-2024-5640 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.14.8 3.14.8 2024-06-06
CVE-2024-3997 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.14.2 3.14.2 2024-05-22
CVE-2024-4339 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.14.4 3.14.4 2024-05-07
CVE-2024-1730 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.14.1 3.14.1 2024-04-19

CVE-2025-14277

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Source: CVE.org

CVE-2025-68500

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

Source: Wordfence

CVE-2024-12043

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-8442

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-5640

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-3997

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-4339

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-1730

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images from URLs, and html tags used in widgets in all versions up to, and including, 3.14.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

+ 12 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-32681 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Missing Authorization High 8.8 < 3.13.3 3.13.3 2024-04-17
CVE-2024-32682 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Missing Authorization High 8.8 < 3.13.3 3.13.3 2024-04-17
CVE-2024-30186 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.13.2 3.13.2 2024-03-25
CVE-2024-1508 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.13.3 3.13.3 2024-03-12
CVE-2024-1507 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.13.4 3.13.4 2024-03-12
CVE-2024-1506 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.13.2 3.13.2 2024-03-06
CVE-2024-24883 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.11.11 Missing Authorization Medium 4.3 < 3.11.11 3.11.11 2024-02-05
CVE-2023-33999 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.8.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.3 3.8.3 2023-07-18
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Missing Authorization Medium 6.3 < 2.7.0 2.7.0 2022-03-04
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Unknown < 2.7.0 2.7.0 2022-02-28
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 Unknown < 2.7.0 2.7.0 2022-02-28
CVE-2026-4341 Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.11 Unknown < 4.1.11 4.1.11 0000-00-00

CVE-2024-32681

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dci_sdk_insights, dci_sdk_dismiss_notice, and rc_sdk_dismiss_notice functions in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.

Source: Wordfence

CVE-2024-32682

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss() function in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.

Source: Wordfence

CVE-2024-30186

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.2). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.2. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-1508

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3). RandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-1507

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3). Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-1506

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-24883

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.11.11). Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.11.11. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2023-33999

Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.8.3). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.8.3.

Source: Patchstack

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

Source: Wordfence

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).

Source: Patchstack

Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0

Sensitive Information Disclosure vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).

Source: Patchstack

CVE-2026-4341

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget setting using `echo` without any escaping function. The setting value is stored in `_elementor_data` post meta via `update_post_meta`. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.