CVE-2026-105875: WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BdThemes Prime Slider – Addons For Elementorto a version that resolves this vulnerability.Fixed in 4.7.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability requires low-privileged access (PR:L) and user interaction (UI:R). It can be exploited remotely over the network with low attack complexity.
What versions are affected?
Prime Slider – Addons For Elementor is affected through version 4.6.2. The available data does not identify a fixed version.
What is the potential impact?
Successful exploitation can result in stored cross-site scripting. The supplied vector indicates low impacts to confidentiality, integrity, and availability, with scope changed.