Impact
The Biggopti Library used by several BDThemes WordPress plugins is susceptible to Cross‑Site Scripting. The flaw arises when the library processes the 'display_id' parameter received from the Sigmative API without proper output escaping. An attacker who can control the content of that parameter can inject arbitrary JavaScript, which will execute when a site visitor loads a page that incorporates the data.
Affected Systems
Affected WordPress plugins include BDThemes Element Pack Addons for Elementor, Live Copy Paste for Elementor, Pixel Gallery Addons for Elementor, Prime Slider, Smart Admin Assistant, Ultimate Post Kit, and Ultimate Store Kit. The vulnerability is present in the Biggopti Library bundled with these plugins in the versions referenced in the advisories (e.g., Element Pack 8.7.14, Prime Slider 4.4.5, Live Copy Paste 1.5.4, Pixel Gallery 2.1.14, Smart Admin Assistant 2.2.0, Ultimate Post Kit 4.2.0, and Ultimate Store Kit 3.0.7).
Risk and Exploitability
The CVSS base score of 5.4 indicates a medium‑severity flaw. The EPSS score of less than 1% suggests that exploitation attempts are currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious 'display_id' value from the Sigmative API; if the attacker has control of that server, the injected script will run in the context of any site visitor, enabling credential theft or defacement.
OpenCVE Enrichment