Stored Cross-Site Scripting Vulnerability in Prime Slider Addons for Elementor by bdThemes
CVE-2026-4341

6.4MEDIUM

What is CVE-2026-4341?

The Prime Slider – Addons for Elementor, developed by bdThemes, suffers from a Stored Cross-Site Scripting vulnerability that can be exploited by authenticated attackers with Author-level privileges and above. This vulnerability exists due to insufficient input sanitization and output escaping of the 'follow_us_text' setting within the Mount widget. The flaw arises in the render_social_link() function, which outputs this setting directly without proper escaping. As a result, attackers can inject malicious web scripts, which will execute when users access affected pages, posing significant risks to site integrity and user safety.

Affected Version(s)

Prime Slider – Addons for Elementor 0 <= 4.1.10

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
Itthidej Aramsri
.