Where
-Infinity
0

BdThemes Instant Image GeneratorWordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability

Risk 39
Severity
6.4
First published (updated )

BdThemes Element Pack Elementor AddonsWordPress Element Pack Elementor Addons plugin <= 8.4.2 - SQL Injection vulnerability

Risk 47
Severity
7.6
First published (updated )

bdthemes Ultimate Post KitWordPress Ultimate Post Kit plugin <= 4.0.21 - Broken Access Control vulnerability

Risk 39
Severity
6.4
First published (updated )

bdthemes ZoloBlocksWordPress ZoloBlocks plugin <= 2.3.11 - Broken Access Control vulnerability

Risk 27
Severity
5.3
First published (updated )

BdThemes ZoloBlocksWordPress ZoloBlocks Plugin <= 2.3.11 - Server Side Request Forgery (SSRF) Vulnerability

Risk 35
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BdThemes Ultimate Store Kit Elementor AddonsWordPress Ultimate Store Kit Elementor Addons plugin <= 2.8.6 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

BdThemes ZoloBlocksWordPress ZoloBlocks plugin <= 2.3.12 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

BdThemes ZoloBlocksWordPress ZoloBlocks Plugin <= 2.3.2 - Local File Inclusion Vulnerability

Risk 70
Severity
7.5
First published (updated )

Element Pack Elementor Addons and TemplatesElement Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )

Element Pack Element Pack AddonsElement Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute

Risk 28
Severity
6.4
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BdThemes Element Pack ProWordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerability

Risk 22
Severity
4.3
First published (updated )

Ultimate Store Kit Elementor AddonsUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.4.1 - Cross-Site Request Forgery to Limited User Meta Update

Risk 22
Severity
4.3
First published (updated )

Element Pack Element Pack Addons for ElementorElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

BdThemes Ultimate Store Kit Elementor AddonsWordPress Ultimate Store Kit Elementor Addons plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability

Risk 26
Severity
6.5
EPSS
0.03%
First published (updated )

BdThemes Ultimate Store Kit Elementor AddonsWordPress Ultimate Store Kit Elementor Addons plugin <= 2.3.0 - Broken Access Control vulnerability

Risk 17
Severity
4.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

bdthemes Prime Slider WordpressPrime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

bdthemes Element Pack WordpressElement Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Element Pack Elementor AddonsElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization

Risk 22
Severity
4.3
First published (updated )

Element Pack Elementor AddonsElement Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget

Risk 29
Severity
6.4
EPSS
0.04%
First published (updated )

Element Pack Elementor AddonsElement Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Element Pack Elementor AddonsElement Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

Risk 34
Severity
5.4
First published (updated )

BdThemes Instant Image GeneratorWordPress Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin <= 1.5.2 - Arbitrary File Upload vulnerability

Risk 47
Severity
10
First published (updated )

bdthemes Prime Slider WordpressPrime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget

Risk 28
Severity
6.4
EPSS
0.07%
First published (updated )

bdthemes Element Pack WordpressElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

bdthemes Element Pack WordpressElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Risk 28
Severity
6.5
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

bdthemes Element Pack WordpressElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

bdthemes Element Pack WordpressElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget

Risk 39
Severity
6.4
First published (updated )

bdthemes Element Pack Elementor AddonsWordPress Element Pack Elementor Addons plugin <= 5.7.5 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
First published (updated )

Ultimate Store Kit Elementor AddonsUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object Injection

Risk 61
Severity
9.8
EPSS
0.14%
First published (updated )

Ultimate Store Kit Elementor AddonsUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203