Executive brief
Prime Slider is a popular WordPress plugin used to create interactive sliders and carousels on websites. A security flaw allows users with 'Author' level permissions or higher to inject malicious scripts into specific slider settings. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the Mount widget. Specifically, the render_social_link() function in modules/mount/widgets/mount.php outputs the 'follow_us_text' setting using a PHP echo statement without proper escaping. An authenticated attacker with Author-level permissions or higher can inject arbitrary web scripts into the '_elementor_data' post meta. These scripts execute in the context of a user's browser whenever they visit the compromised page. The issue is present in all versions up to and including 4.1.10.
Affected products
- BdThemes Prime Slider – Addons for Elementor up to, and including, 4.1.10
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
References
- https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.1.9/modules/mount/widgets/mount.php
- https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.1.9/modules/mount/widgets/mount.php
- https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/trunk/modules/mount/widgets/mount.php
- https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/trunk/modules/mount/widgets/mount.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3493676%40bdthemes-prime-slider-lite&new=3493676%40bdthemes-prime-slider-lite&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4a2ef416-4354-4e09-b9be-e36c1f655110?source=cve