Server-Side Request Forgery Vulnerability in bdthemes Prime Slider Addon for Elementor
CVE-2025-68500

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-68500?

The bdthemes Prime Slider – Addons For Elementor is susceptible to a Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to send crafted requests to internal resources, potentially leading to sensitive data exposure. This security flaw affects all versions of the Prime Slider up to and including 4.0.10, highlighting the need for users to implement protective measures to mitigate unauthorized access to their server environments. It is crucial to update to patched versions to ensure the integrity of your WordPress site.

Affected Version(s)

Prime Slider – Addons For Elementor 0 <= 4.0.10

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NumeX | Patchstack Bug Bounty Program
.