Prime Slider – Addons For Elementor <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via UIkit Component Attributes
- ID
- WPSEC-2026-0489
- Plugin
- Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons (bdthemes-prime-slider-lite)
- Affected
- all versions before 4.7.0
- Remediation
- Update to 4.7.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Prime Slider – Addons For Elementor on WPSec AttackSurface
- Fix released
- Published
Description
The Prime Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via UIkit component attributes (such as 'data-bdt-svg' and 'data-bdt-lightbox-panel') in post content in all versions up to, and including, 4.6.2. This is due to insufficient input sanitization: WordPress's post content filtering lets these data attributes through, and the bundled UIkit script boots a component from any element carrying them without validating the component options. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user, such as an administrator previewing the post, accesses a page that loads the Prime Slider script bundle, for example a page containing a Prime Slider widget.
References
- https://wpsec.com/vuln/WPSEC-2026-0489/
- https://plugins.svn.wordpress.org/bdthemes-prime-slider-lite/tags/4.7.0/
- https://wordpress.org/plugins/bdthemes-prime-slider-lite/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS