Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

bdthemes — Vulnerabilities & Security Advisories 95

Browse all 95 CVE security advisories affecting bdthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Bdthemes operates as a developer of WordPress themes and plugins, primarily targeting the e-commerce and lifestyle sectors. Security audits have identified eighty-one Common Vulnerabilities and Exposures (CVEs) associated with its portfolio, indicating a persistent pattern of insecure coding practices. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, several instances of privilege escalation and broken access control have been documented, allowing unauthorized users to manipulate administrative functions or access sensitive files. These flaws frequently arise from outdated libraries and a lack of rigorous security testing during the development lifecycle. While some issues have been patched in subsequent updates, the high volume of recorded CVEs suggests that security remains a secondary priority compared to feature deployment, posing significant risks to sites relying on these components.

Found 10 results / 95 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-66574 WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2026-09-17
CVE-2026-65502 WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability — Element Pack Elementor Addons CWE-290 5.3 Medium 2026-08-06
CVE-2026-40745 WordPress Element Pack Elementor Addons plugin <= 8.4.2 - SQL Injection vulnerability — Element Pack Elementor Addons CWE-89 7.6 High 2026-04-15
CVE-2025-31413 WordPress Element Pack Elementor Addons plugin <= 8.3.13 - Cross Site Request Forgery (CSRF) vulnerability — Element Pack Elementor Addons CWE-352 4.3 Medium 2026-01-22
CVE-2024-47392 WordPress Element Pack Elementor Addons plugin <= 5.7.5 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2024-10-05
CVE-2024-39667 WordPress Element Pack Elementor Addons plugin <= 5.6.11 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2024-08-01
CVE-2024-32572 WordPress Element Pack Elementor Addons plugin <= 5.6.0 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2024-04-18
CVE-2024-30496 WordPress Element Pack Lite plugin <= 5.5.3 - SQL Injection vulnerability — Element Pack Elementor Addons CWE-89 8.5 High 2024-03-29
CVE-2024-30185 WordPress Element Pack Elementor Addons plugin <= 5.5.3 - Cross Site Scripting (XSS) vulnerability — Element Pack Elementor Addons CWE-79 6.5 Medium 2024-03-27
CVE-2024-24840 WordPress Element Pack Elementor Addons plugin <= 5.4.11 - Broken Access Control on Duplicate Post vulnerability — Element Pack Elementor Addons CWE-862 4.3 Medium 2024-03-23

This page lists every published CVE security advisory associated with bdthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.