Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

bdthemes — Vulnerabilities & Security Advisories 95

Browse all 95 CVE security advisories affecting bdthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Bdthemes operates as a developer of WordPress themes and plugins, primarily targeting the e-commerce and lifestyle sectors. Security audits have identified eighty-one Common Vulnerabilities and Exposures (CVEs) associated with its portfolio, indicating a persistent pattern of insecure coding practices. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, several instances of privilege escalation and broken access control have been documented, allowing unauthorized users to manipulate administrative functions or access sensitive files. These flaws frequently arise from outdated libraries and a lack of rigorous security testing during the development lifecycle. While some issues have been patched in subsequent updates, the high volume of recorded CVEs suggests that security remains a secondary priority compared to feature deployment, posing significant risks to sites relying on these components.

CVE ID Title CVSS Severity Published
CVE-2026-93527 WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability — Live Copy Paste for Elementor CWE-89 8.5 High 2026-09-23
CVE-2026-92991 Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API — Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator CWE-79 5.4 Medium 2026-09-18
CVE-2026-66574 WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2026-09-17
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field — SigmaForms Pro – AI Generated Forms CWE-22 9.8 Critical 2026-09-02
CVE-2026-14494 Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field — SigmaForms Pro – AI Generated Forms CWE-434 9.8 Critical 2026-08-29
CVE-2026-65502 WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability — Element Pack Elementor Addons CWE-290 5.3 Medium 2026-08-06
CVE-2026-25403 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability — Ultimate Store Kit Elementor Addons CWE-862 6.5 Medium 2026-08-06
CVE-2026-0673 Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons CWE-93 5.3 Medium 2026-08-06
CVE-2026-65505 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability — Ultimate Store Kit Elementor Addons CWE-497 5.3 Medium 2026-07-23
CVE-2026-65503 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability — Ultimate Store Kit Elementor Addons CWE-79 6.5 Medium 2026-07-23
CVE-2026-57413 WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability — Instant Image Generator CWE-918 6.4 Medium 2026-07-13
CVE-2025-63079 WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Control vulnerability — Live Copy Paste for Elementor CWE-862 4.3 Medium 2026-06-26
CVE-2026-52705 WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary File Upload vulnerability — SigmaForms Pro – AI Generated Forms CWE-434 9.0 Critical 2026-06-17
CVE-2026-40721 WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability — Element Pack Pro CWE-98 7.5 High 2026-06-17
CVE-2026-40745 WordPress Element Pack Elementor Addons plugin <= 8.4.2 - SQL Injection vulnerability — Element Pack Elementor Addons CWE-89 7.6 High 2026-04-15
CVE-2026-4655 Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget — Element Pack – Widgets, Templates & Addons for Elementor CWE-79 6.4 Medium 2026-04-08
CVE-2026-4341 Prime Slider <= 4.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter — Prime Slider – Addons for Elementor CWE-79 6.4 Medium 2026-04-08
CVE-2026-24362 WordPress Ultimate Post Kit plugin <= 4.0.21 - Broken Access Control vulnerability — Ultimate Post Kit CWE-862 6.4 Medium 2026-03-25
CVE-2026-1793 Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read — Element Pack – Widgets, Templates & Addons for Elementor CWE-22 6.5 Medium 2026-02-15
CVE-2025-31413 WordPress Element Pack Elementor Addons plugin <= 8.3.13 - Cross Site Request Forgery (CSRF) vulnerability — Element Pack Elementor Addons CWE-352 4.3 Medium 2026-01-22
CVE-2026-0808 Spin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter — Spin Wheel – Interactive spinning wheel that offers coupons CWE-602 5.3 Medium 2026-01-17
CVE-2025-69336 WordPress Ultimate Store Kit Elementor Addons plugin <= 2.9.4 - Broken Access Control vulnerability — Ultimate Store Kit Elementor Addons CWE-862 4.3 Medium 2026-01-06
CVE-2025-68500 WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) vulnerability — Prime Slider – Addons For Elementor CWE-918 4.9 Medium 2025-12-24
CVE-2025-14277 Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery — Prime Slider – Addons for Elementor CWE-918 4.3 Medium 2025-12-18
CVE-2025-13196 Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget — Element Pack – Widgets, Templates & Addons for Elementor CWE-79 5.4 Medium 2025-11-18
CVE-2025-12134 ZoloBlocks <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable — ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns CWE-862 5.3 Medium 2025-10-24
CVE-2025-49903 WordPress ZoloBlocks plugin <= 2.3.11 - Broken Access Control vulnerability — ZoloBlocks CWE-862 5.3 Medium 2025-10-22
CVE-2025-11536 Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery — Element Pack – Widgets, Templates & Addons for Elementor CWE-918 5.0 Medium 2025-10-20
CVE-2025-9075 ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting — ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns CWE-79 6.4 Medium 2025-10-01
CVE-2025-60161 WordPress ZoloBlocks Plugin <= 2.3.11 - Server Side Request Forgery (SSRF) Vulnerability — ZoloBlocks CWE-918 5.4 Medium 2025-09-26

This page lists every published CVE security advisory associated with bdthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.