Stored Cross-Site Scripting Vulnerability in Prime Slider Addons for Elementor by bdThemes
CVE-2026-4341
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-4341?
The Prime Slider β Addons for Elementor, developed by bdThemes, suffers from a Stored Cross-Site Scripting vulnerability that can be exploited by authenticated attackers with Author-level privileges and above. This vulnerability exists due to insufficient input sanitization and output escaping of the 'follow_us_text' setting within the Mount widget. The flaw arises in the render_social_link() function, which outputs this setting directly without proper escaping. As a result, attackers can inject malicious web scripts, which will execute when users access affected pages, posing significant risks to site integrity and user safety.
Affected Version(s)
Prime Slider β Addons for Elementor 0 <= 4.1.10