Server-Side Request Forgery Vulnerability in bdthemes Prime Slider Addon for Elementor
CVE-2025-68500

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-68500?

The bdthemes Prime Slider – Addons For Elementor is susceptible to a Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to send crafted requests to internal resources, potentially leading to sensitive data exposure. This security flaw affects all versions of the Prime Slider up to and including 4.0.10, highlighting the need for users to implement protective measures to mitigate unauthorized access to their server environments. It is crucial to update to patched versions to ensure the integrity of your WordPress site.

Affected Version(s)

Prime Slider – Addons For Elementor <= n/a

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NumeX | Patchstack Bug Bounty Program
.
CVE-2025-68500 : Server-Side Request Forgery Vulnerability in bdthemes Prime Slider Addon for Elementor