Prime Slider – Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/bdthemes-prime-slider-lite

Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.

100K active installs v4.1.13 PHP 7.4.0+ WP 5.0.0+ Updated Apr 9, 2026
content-sliderelementor-addonimage-sliderlayer-slidervideo-slider
95
A · Safe
CVEs total16
Unpatched0
Last CVEApr 7, 2026
Safety Verdict

Is Prime Slider – Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 95/100

Prime Slider – Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

16 known CVEsLast CVE: Apr 7, 2026Updated 1mo ago
Risk Assessment

The plugin 'bdthemes-prime-slider-lite' v4.1.10 presents a mixed security posture. While it demonstrates good practices in output escaping (91%) and a reasonable number of nonce and capability checks relative to its entry points, significant concerns arise from its attack surface and vulnerability history. The presence of 3 unprotected AJAX handlers out of 21 total entry points is a notable weakness, as these can be directly exploited by unauthenticated users. Furthermore, the plugin has a history of 15 known CVEs, predominantly medium severity, with common types including SSRF, missing authorization, and XSS. While there are currently no unpatched CVEs, this extensive history suggests a recurring pattern of security flaws that may not have been fully addressed, despite the recent vulnerability recorded in late 2025. The taint analysis, while showing no critical or high severity flows, did identify 2 flows with unsanitized paths, which could potentially lead to vulnerabilities if exploited in conjunction with other weaknesses.

Overall, the plugin exhibits strengths in code-level sanitization and escaping. However, the unprotected entry points and the extensive history of medium-severity vulnerabilities, particularly those related to authorization and input sanitization, indicate a need for increased vigilance and a thorough review of its authorization mechanisms. The lack of critical or high severity issues in taint analysis is a positive sign, but the underlying susceptibility to medium-severity attacks as evidenced by its history remains a concern.

Key Concerns

  • Unprotected AJAX handlers
  • Significant vulnerability history (15 CVEs)
  • Flows with unsanitized paths found
Vulnerabilities
16 published

Prime Slider – Addons for Elementor Security Vulnerabilities

CVEs by Year

12 CVEs in 2024
2024
3 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
15
Low
1

16 total CVEs

CVE-2026-4341medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider <= 4.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter

Apr 7, 2026 Patched in 4.1.11 (1d)
CVE-2025-14277medium · 4.3Server-Side Request Forgery (SSRF)

Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery

Dec 17, 2025 Patched in 4.1.0 (1d)
CVE-2025-68500medium · 6.4Server-Side Request Forgery (SSRF)

Prime Slider – Addons For Elementor <= 4.0.10 - Authenticated (Subscriber+) Server-Side Request Forgery

Dec 13, 2025 Patched in 4.1.0 (24d)
CVE-2024-12043medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 22, 2025 Patched in 3.16.6 (1d)
CVE-2024-8442medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget

Nov 6, 2024 Patched in 3.15.19 (1d)
CVE-2024-5640medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pacific Widget

Jun 6, 2024 Patched in 3.14.8 (1d)
CVE-2024-3997medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pagepiling Widget

May 22, 2024 Patched in 3.14.2 (1d)
CVE-2024-4339medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2024 Patched in 3.14.4 (3d)
CVE-2024-1730medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) <= 3.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 19, 2024 Patched in 3.14.1 (1d)
CVE-2024-32682medium · 5.3Missing Authorization

Prime Slider – Addons For Elementor <= 3.13.2 - Missing Authorization to Notice Dismissal

Apr 17, 2024 Patched in 3.13.3 (7d)
CVE-2024-32681low · 3.1Missing Authorization

Prime Slider – Addons For Elementor <= 3.13.2 - Missing Authorization

Apr 17, 2024 Patched in 3.13.3 (7d)
CVE-2024-30186medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via title

Mar 25, 2024 Patched in 3.13.2 (4d)
CVE-2024-1507medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor <= 3.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rubix Widget

Mar 12, 2024 Patched in 3.13.4 (3d)
CVE-2024-1508medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mercury Widget

Mar 12, 2024 Patched in 3.13.3 (2d)
CVE-2024-1506medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Prime Slider – Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget

Mar 6, 2024 Patched in 3.13.2 (1d)
CVE-2024-24883medium · 5.4Incorrect Authorization

Prime Slider – Addons For Elementor <= 3.11.10 - Incorrect Authorization via bdt_duplicate_as_draft

Feb 5, 2024 Patched in 3.11.11 (4d)
Version History

Prime Slider – Addons for Elementor Release Timeline

v4.1.13Current
v4.1.123 files changed
v4.1.118 files changed
v4.1.101 CVE12 files changed
v4.1.91 CVE15 files changed
v4.1.71 CVE3 files changed
v4.1.61 CVE4 files changed
v4.1.51 CVE8 files changed
v4.1.41 CVE41 files changed
v4.1.31 CVE6 files changed
v4.1.21 CVE3 files changed
v4.1.11 CVE23 files changed
v4.1.01 CVE11 files changed
v4.0.103 CVEs3 files changed
v4.0.93 CVEs3 files changed
v4.0.83 CVEs5 files changed
v4.0.73 CVEs3 files changed
v4.0.63 CVEs7 files changed
v4.0.53 CVEs5 files changed
v4.0.43 CVEs18 files changed
Code Analysis
Analyzed Mar 16, 2026

Prime Slider – Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
135
1329 escaped
Nonce Checks
21
Capability Checks
33
File Operations
13
External Requests
5
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

91% escaped1464 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
bdt_duplicate_as_draft (includes\class-duplicator.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Prime Slider – Addons for Elementor Attack Surface

Entry Points21
Unprotected3

AJAX Handlers 21

authwp_ajax_ps_admin_api_biggopti_dismissadmin\admin-api-biggopti.php:20
authwp_ajax_prime_slider_biggoptiesadmin\admin-biggopti.php:24
authwp_ajax_ps_fetch_api_biggoptiesadmin\admin-biggopti.php:27
authwp_ajax_ps_save_white_labeladmin\admin-settings.php:75
authwp_ajax_ps_revoke_white_label_tokenadmin\admin-settings.php:76
authwp_ajax_ps_install_pluginadmin\admin-settings.php:80
authwp_ajax_ps_save_custom_codeadmin\admin-settings.php:94
authwp_ajax_ps_rollback_versionadmin\class-rollback-version.php:22
authwp_ajax_prime_slider_settings_saveadmin\class-settings-api.php:24
authwp_ajax_rc_sdk_insightsincludes\feedback-hub\rc-biggopti.php:45
authwp_ajax_rc_sdk_dismiss_biggoptiincludes\feedback-hub\rc-biggopti.php:46
authwp_ajax_ps_get_pluginsincludes\setup-wizard\class-remote-data-handler.php:40
noprivwp_ajax_ps_get_pluginsincludes\setup-wizard\class-remote-data-handler.php:41
authwp_ajax_setup_wizard_install_pluginsincludes\setup-wizard\init.php:53
authwp_ajax_import_elementor_templateincludes\setup-wizard\init.php:406
authwp_ajax_import_ps_elementor_bundle_templateincludes\setup-wizard\init.php:501
authwp_ajax_import_ps_elementor_bundle_runner_templateincludes\setup-wizard\init.php:596
authwp_ajax_ps_get_pluginsincludes\setup-wizard\prime-slider-others-plugin.php:26
noprivwp_ajax_ps_get_pluginsincludes\setup-wizard\prime-slider-others-plugin.php:27
authwp_ajax_ps_install_pluginincludes\setup-wizard\prime-slider-others-plugin.php:28
authwp_ajax_prime_slider_dynamic_select_input_datatraits\query-controls\select-input\dynamic-select-input-module.php:42
WordPress Hooks 64
actionwp_dashboard_setupadmin\admin-feeds.php:26
actionadmin_initadmin\admin-settings.php:43
actionadmin_menuadmin\admin-settings.php:44
actionadmin_noticesadmin\admin-settings.php:60
actionadmin_headadmin\admin-settings.php:77
actionadmin_enqueue_scriptsadmin\admin-settings.php:98
actionadmin_initadmin\admin-settings.php:434
actionadmin_menuadmin\admin-settings.php:435
actionadmin_noticesadmin\admin-settings.php:438
actionadmin_initadmin\admin.php:28
actionadmin_enqueue_scriptsadmin\admin.php:29
actionadmin_initadmin\admin.php:32
actionafter_setup_themeadmin\admin.php:34
actionadmin_initadmin\admin.php:38
filtergettextadmin\admin.php:65
actionpre_current_active_pluginsadmin\admin.php:68
filterplugin_row_metaadmin\admin.php:71
actionupgrader_pre_installadmin\class-rollback-version.php:25
actionupgrader_process_completeadmin\class-rollback-version.php:28
actionupgrader_process_completeadmin\class-rollback-version.php:31
actionactivated_pluginadmin\class-rollback-version.php:34
actionactivated_pluginadmin\class-rollback-version.php:37
actionplugins_loadedadmin\class-rollback-version.php:40
actionadmin_initadmin\class-rollback-version.php:43
actionadmin_initadmin\class-rollback-version.php:46
actionadmin_enqueue_scriptsadmin\class-settings-api.php:22
actionelementor/widgets/registerbase\prime-slider-module-base.php:80
actioninitbdthemes-prime-slider.php:49
actionadmin_noticesbdthemes-prime-slider.php:109
actionwp_headbdthemes-prime-slider.php:124
actionwp_footerbdthemes-prime-slider.php:125
actionplugins_loadedbdthemes-prime-slider.php:128
actionadmin_initbdthemes-prime-slider.php:181
actionadmin_action_bdt_duplicate_as_draftincludes\class-duplicator.php:20
filterpost_row_actionsincludes\class-duplicator.php:21
filterpage_row_actionsincludes\class-duplicator.php:22
filterwpml_elementor_widgets_to_translateincludes\class-elements-wpml-compatibility.php:29
actionadmin_enqueue_scriptsincludes\feedback-hub\rc-biggopti.php:124
actionadmin_noticesincludes\feedback-hub\rc-biggopti.php:127
actionelementor/editor/after_enqueue_scriptsincludes\live-copy\class-live-copy.php:9
actioninitincludes\setup-wizard\class-remote-data-handler.php:38
actioninitincludes\setup-wizard\class-remote-data-handler.php:553
actionadmin_enqueue_scriptsincludes\setup-wizard\init.php:54
actionadmin_initincludes\setup-wizard\init.php:55
actionadmin_initincludes\setup-wizard\init.php:56
actionadmin_initincludes\setup-wizard\init.php:57
filterauto_update_translationincludes\setup-wizard\init.php:60
actionadmin_headincludes\setup-wizard\init.php:70
actionadmin_footerincludes\setup-wizard\init.php:122
actionadmin_headincludes\setup-wizard\init.php:162
actionelementor/elements/categories_registeredloader.php:343
actionelementor/initloader.php:344
actionelementor/editor/after_enqueue_stylesloader.php:345
actionwp_enqueue_scriptsloader.php:347
actionwp_enqueue_scriptsloader.php:348
actionwp_enqueue_scriptsloader.php:349
actionwp_enqueue_scriptsloader.php:350
actionelementor/preview/enqueue_stylesloader.php:352
actionelementor/editor/after_enqueue_scriptsloader.php:353
actioninitloader.php:382
actionpre_get_poststraits\query-controls\group-query\group-control-query.php:702
actionpre_get_poststraits\query-controls\group-query\group-control-query.php:704
filterfound_poststraits\query-controls\group-query\group-control-query.php:705
actionelementor/controls/registertraits\query-controls\select-input\dynamic-select.php:123
Maintenance & Trust

Prime Slider – Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version7.4.0
Downloads5.9M

Community Trust

Rating90/100
Number of ratings80
Active installs100K
Developer Profile

Prime Slider – Addons for Elementor Developer Profile

bdthemes

24 plugins · 250K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
21 days
View full developer profile
Detection Fingerprints

How We Detect Prime Slider – Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bdthemes-prime-slider-lite/assets/css/prime-slider.css/wp-content/plugins/bdthemes-prime-slider-lite/assets/js/prime-slider.js/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/slick/slick.css/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/swiper/swiper-bundle.min.css/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/animate/animate.min.css/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/fontawesome/css/all.min.css/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/slick/slick.min.js/wp-content/plugins/bdthemes-prime-slider-lite/assets/vendor/swiper/swiper-bundle.min.js+2 more
Generator Patterns
Prime Slider 4.1.10
Script Paths
/wp-content/plugins/bdthemes-prime-slider-lite/assets/js/prime-slider.js/wp-content/plugins/bdthemes-prime-slider-lite/assets/js/prime-slider-core.js/wp-content/plugins/bdthemes-prime-slider-lite/assets/js/frontend.js
Version Parameters
bdthemes-prime-slider-lite/assets/css/prime-slider.css?ver=bdthemes-prime-slider-lite/assets/js/prime-slider.js?ver=bdthemes-prime-slider-lite/assets/vendor/slick/slick.css?ver=bdthemes-prime-slider-lite/assets/vendor/swiper/swiper-bundle.min.css?ver=bdthemes-prime-slider-lite/assets/vendor/animate/animate.min.css?ver=bdthemes-prime-slider-lite/assets/vendor/fontawesome/css/all.min.css?ver=bdthemes-prime-slider-lite/assets/vendor/slick/slick.min.js?ver=bdthemes-prime-slider-lite/assets/vendor/swiper/swiper-bundle.min.js?ver=bdthemes-prime-slider-lite/assets/js/prime-slider-core.js?ver=bdthemes-prime-slider-lite/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
prime-slider-bdt-prime-sliderbdt-ps-main-sliderbdt-ps-navigation
HTML Comments
<!-- Elementor Live Preview --><!-- Elementor Edit Mode --><!-- Prime Slider: Inject custom CSS/JS -->
Data Attributes
data-elementor-iddata-elementor-type
JS Globals
PrimeSliderSettingsPrimeSliderFrontend
REST Endpoints
/wp-json/bdthemes-prime-slider-lite/v1/get-posts/wp-json/bdthemes-prime-slider-lite/v1/get-terms
Shortcode Output
[prime_slider][bdps][prime_slider id='{id}']
FAQ

Frequently Asked Questions about Prime Slider – Addons for Elementor