Known vulnerabilities, PHP compatibility and safer alternatives for the Bdthemes Prime Slider Lite WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
- Slug:
bdthemes-prime-slider-lite
Maintenance status
Known vulnerabilities
17 known CVEs on file for Bdthemes Prime Slider Lite.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14277
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 |
Server-Side Request Forgery (SSRF) |
Medium
4.3
|
< 4.1.0
|
4.1.0 |
2025-12-17 |
—
|
|
CVE-2025-68500
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.0 |
Server-Side Request Forgery (SSRF) |
Medium
4.9
|
< 4.1.0
|
4.1.0 |
2025-12-13 |
—
|
|
CVE-2024-12043
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.16.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 3.16.6
|
3.16.6 |
2025-01-22 |
—
|
|
CVE-2024-8442
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.15.19 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.15.19
|
3.15.19 |
2024-11-06 |
—
|
|
CVE-2024-5640
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.14.8
|
3.14.8 |
2024-06-06 |
—
|
|
CVE-2024-3997
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.14.2
|
3.14.2 |
2024-05-22 |
—
|
|
CVE-2024-4339
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.14.4
|
3.14.4 |
2024-05-07 |
—
|
|
CVE-2024-1730
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.14.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.14.1
|
3.14.1 |
2024-04-19 |
—
|
CVE-2025-14277
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Source:
CVE.org
CVE-2025-68500
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Source:
Wordfence
CVE-2024-12043
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-8442
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-5640
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-3997
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-4339
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-1730
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images from URLs, and html tags used in widgets in all versions up to, and including, 3.14.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
+ 12 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-32681
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Missing Authorization |
High
8.8
|
< 3.13.3
|
3.13.3 |
2024-04-17 |
—
|
|
CVE-2024-32682
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Missing Authorization |
High
8.8
|
< 3.13.3
|
3.13.3 |
2024-04-17 |
—
|
|
CVE-2024-30186
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.5
|
< 3.13.2
|
3.13.2 |
2024-03-25 |
—
|
|
CVE-2024-1508
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.13.3
|
3.13.3 |
2024-03-12 |
—
|
|
CVE-2024-1507
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.13.4
|
3.13.4 |
2024-03-12 |
—
|
|
CVE-2024-1506
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.13.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.13.2
|
3.13.2 |
2024-03-06 |
—
|
|
CVE-2024-24883
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.11.11 |
Missing Authorization |
Medium
4.3
|
< 3.11.11
|
3.11.11 |
2024-02-05 |
—
|
|
CVE-2023-33999
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 3.8.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 3.8.3
|
3.8.3 |
2023-07-18 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
Missing Authorization |
Medium
6.3
|
< 2.7.0
|
2.7.0 |
2022-03-04 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
— |
Unknown
|
< 2.7.0
|
2.7.0 |
2022-02-28 |
—
|
|
—
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0 |
— |
Unknown
|
< 2.7.0
|
2.7.0 |
2022-02-28 |
—
|
|
CVE-2026-4341
|
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 4.1.11 |
— |
Unknown
|
< 4.1.11
|
4.1.11 |
0000-00-00 |
—
|
CVE-2024-32681
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dci_sdk_insights, dci_sdk_dismiss_notice, and rc_sdk_dismiss_notice functions in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.
Source:
Wordfence
CVE-2024-32682
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss() function in versions up to, and including, 3.13.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices.
Source:
Wordfence
CVE-2024-30186
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.2).
Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.2.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-1508
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3).
RandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-1507
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.13.3).
Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.13.3.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-1506
The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-24883
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.11.11).
Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.11.11.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2023-33999
Update the WordPress Prime Slider – Addons For Elementor plugin to the latest available version (at least 3.8.3).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Prime Slider – Addons For Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.8.3.
Source:
Patchstack
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Source:
Wordfence
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).
Source:
Patchstack
Prime Slider Addons for Elementor [bdthemes-prime-slider-lite] < 2.7.0
Sensitive Information Disclosure vulnerability discovered in WordPress Prime Slider – Addons For Elementor plugin (versions <= 2.6.2).
Source:
Patchstack
CVE-2026-4341
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget setting using `echo` without any escaping function. The setting value is stored in `_elementor_data` post meta via `update_post_meta`. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.