Bdthemes develops a focused portfolio of WordPress plugins and themes for e-commerce and content presentation, including Element Pack, Prime Slider, and Ultimate Store Kit, which collectively achieve significant adoption within the WordPress plugin ecosystem. The vendor's vulnerability profile centers on application-layer input handling and authorization issues characteristic of web-facing WordPress extensions, with recurring weaknesses in cross-site scripting, missing authorization controls, CSRF protection, and deserialization of untrusted data. These plugins' widespread integration into WordPress sites creates a supply-chain risk where a single vulnerability can propagate across thousands of deployments, and the authorization and injection classes recur across the product line, reflecting the common challenges of plugins that process user input and interact with WordPress administration functions. Defenders should monitor this vendor's releases and prioritize patches for internet-facing WordPress instances running its plugins, particularly those handling e-commerce or administrative functionality. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bdthemes over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8030CRITICAL The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Obje | Aug 28, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-5335CRITICAL The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Obje | Aug 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-32682HIGH Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2. | Apr 22, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-30496HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Element | Mar 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-8100MEDIUM The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and includin | Aug 6, 2025 | 5.4 | 22 | NO | NO |
CVE-2024-32681HIGH Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2. | Apr 22, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-1507MEDIUM The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in all versions up to, | Mar 13, 2024 | 5.4 | 21 | NO | NO |
CVE-2024-33568MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, | Jun 4, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-2966HIGH The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in | Apr 11, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-4359MEDIUM The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versio | Aug 12, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bdthemes.
Media articles that mention a CVE ID that affects a product developed by Bdthemes — matched by CVE ID, not by vendor name.