Prime Slider – Addons For Elementor <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via UIkit Component Attributes

Medium 6.4 CWE-79Fixed in 4.7.0
ID
WPSEC-2026-0489
Plugin
Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons (bdthemes-prime-slider-lite)
Affected
all versions before 4.7.0
Remediation
Update to 4.7.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Prime Slider – Addons For Elementor on WPSec AttackSurface
Fix released
Published

Description

The Prime Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via UIkit component attributes (such as 'data-bdt-svg' and 'data-bdt-lightbox-panel') in post content in all versions up to, and including, 4.6.2. This is due to insufficient input sanitization: WordPress's post content filtering lets these data attributes through, and the bundled UIkit script boots a component from any element carrying them without validating the component options. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user, such as an administrator previewing the post, accesses a page that loads the Prime Slider script bundle, for example a page containing a Prime Slider widget.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0