Description
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through <= 4.0.10.
Published: 2025-12-24
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Server‑Side Request Forgery (SSRF) is disclosed in the bdthemes Prime Slider – Addons For Elementor plugin (bdthemes‑prime‑slider‑lite) for all releases up to version 4.0.10. The flaw allows an attacker to force the WordPress host to send arbitrary HTTP or HTTPS requests to internal or external resources, potentially revealing sensitive data or allowing further exploitation. The CVE reference does not detail how the malicious URLs are supplied; however, it is inferred that user‑controlled input is used to construct outbound requests without proper validation or filtering, which is the typical mechanism for SSRF attacks.

Affected Systems

All installations of bdthemes Prime Slider – Addons For Elementor running versions from the initial release through 4.0.10 on WordPress are vulnerable. Versions thereafter are not known to contain the flaw.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, and the EPSS score of less than 1 % suggests low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need the WordPress site to be reachable and would likely send crafted requests through the plugin’s interface or a widget that triggers the server‑side HTTP request functionality. Once exploited, the host could reach internal network services, exfiltrate data, or be used as a pivot to launch additional attacks. The moderate CVSS score combined with the low EPSS rating means that while the risk is limited at present, the potential impact on confidentiality and availability warrants timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade bdthemes Prime Slider – Addons For Elementor to the latest release (4.0.11 or later) where the SSRF code path is removed.
  • If an immediate update is not feasible, deactivate or delete the plugin to eliminate the vulnerable code path.
  • Configure the web server or application firewall to restrict outbound HTTP(S) traffic from the WordPress installation, allowing only trusted destinations.

Generated by OpenCVE AI on April 30, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes prime Slider
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes prime Slider
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through <= 4.0.10.
Title WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References

Subscriptions

Bdthemes Prime Slider
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:28.870Z

Reserved: 2025-12-19T10:16:41.921Z

Link: CVE-2025-68500

cve-icon Vulnrichment

Updated: 2025-12-24T19:12:29.089Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:20.283

Modified: 2026-04-27T19:16:25.797

Link: CVE-2025-68500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:45:06Z

Weaknesses