Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Prime Slider – Addons for Elementor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Prime Slider – Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

Prime Slider – Addons for Elementor is a WordPress plugin developed by Brainstorm Force that has been identified with multiple security weakness types in public vulnerability databases. This page aggregates known security issues affecting this specific product, covering vulnerabilities reported between early 2020 and late 2023. It compiles data from various security advisories, CVE records, and third-party monitoring sources to provide a comprehensive view of the plugin’s security posture over time. Here, researchers and administrators can track the timeline of advisories issued by the vendor or discovered by security researchers. You can analyze specific weakness classes, such as Cross-Site Scripting or SQL Injection, to understand how they manifest within the context of this Elementor addon. The page also allows you to look up the product’s vulnerability history to identify patterns, recurrence of bugs, or the effectiveness of patches. This aggregation serves as a neutral resource for assessing risk without promotional bias. By reviewing these details, you can better understand the security implications of using this tool in your WordPress environment. The information is structured to help you verify whether specific versions are affected and to guide remediation efforts. This resource is intended for informational purposes only and does not endorse any particular vendor or solution. It aims to improve transparency and awareness regarding open-source software security. Users are encouraged to verify findings with official vendor channels before taking action.

Vendor: bdthemes

CVE IDTitleCVSSSeverityPublished
CVE-2026-4341 Prime Slider <= 4.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter CWE-79 6.4 Medium2026-04-08
CVE-2025-68500 WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) vulnerability CWE-918 4.9 Medium2025-12-24
CVE-2025-14277 Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery CWE-918 4.3 Medium2025-12-18
CVE-2024-12043 Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-01-23
CVE-2024-8442 Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget CWE-79 6.4 Medium2024-11-07
CVE-2024-5640 Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pacific Widget CWE-79 6.4 Medium2024-06-07
CVE-2024-3997 Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pagepiling Widget CWE-79 6.4 Medium2024-05-23
CVE-2024-4339 Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-05-09
CVE-2024-32681 WordPress Prime Slider plugin <= 3.13.2 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-04-22
CVE-2024-32682 WordPress Prime Slider plugin <= 3.13.2 - Broken Access Control vulnerability CWE-862 7.1 High2024-04-22
CVE-2024-1730 Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) <= 3.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 5.4 Medium2024-04-20
CVE-2024-30186 WordPress Prime Slider plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-03-27
CVE-2024-24883 WordPress Prime Slider plugin <= 3.11.10 - Broken Access Control on Duplicate Post vulnerability CWE-862 4.3 Medium2024-03-21
CVE-2024-1507 Prime Slider – Addons For Elementor <= 3.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rubix Widget CWE-79 6.4 Medium2024-03-13
CVE-2024-1508 Prime Slider – Addons For Elementor <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mercury Widget CWE-79 6.4 Medium2024-03-13
CVE-2024-1506 Prime Slider – Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget CWE-79 6.4 Medium2024-03-07

All 16 known CVE vulnerabilities affecting Prime Slider – Addons for Elementor with full Chinese analysis, references, and POCs where available.