PatchSiren

bdthemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL bdthemes CVE published 2026-08-29

CVE-2026-14494

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5. This vulnerability exists due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. Several default pre-built templates, including Job Application, Suppor [truncated]

MEDIUM bdthemes CVE published 2026-08-06

CVE-2026-65502

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:14.573Z and has not been modified since then. CVE-2026-65502 is a medium-severity unauthenticated bypass vulnerability in Element Pack Elementor Addons plugin versions <= 8.7.13. The vulnerability allows an attacker to bypass authentication and potentially lead to limited impact on integrit [truncated]

MEDIUM bdthemes CVE published 2026-08-06

CVE-2026-25403

CVE-2026-25403 involves an unauthenticated broken access control vulnerability in Ultimate Store Kit Elementor Addons plugin versions 3.0.5 or earlier. This MEDIUM-severity issue, with a CVSS score of 6.5, may allow unauthorized access and potential operational impact. Users should review and apply patches or mitigations. Evidence is limited to public CVE and NVD sources. Defenders should verify exposed d [truncated]

MEDIUM bdthemes CVE published 2026-07-13

CVE-2026-57413

A Server-Side Request Forgery (SSRF) vulnerability was identified in the bdthemes Instant Image Generator plugin for WordPress, affecting versions from n/a through 2.1.4. This issue allows an attacker to perform Server Side Request Forgery. The vulnerability has a CVSS score of 6.4 and a severity rating of MEDIUM. Administrators and users of the bdthemes Instant Image Generator plugin for WordPress should [truncated]

CRITICAL BDthemes CVE published 2026-06-17

CVE-2026-52705

CVE-2026-52705 is a critical vulnerability (CVSS Score: 9) in the SigmaForms Pro – AI Generated Forms plugin for WordPress, affecting versions up to and including 1.4.5. This vulnerability allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution, data breaches, or other malicious activities. The vulnerability was published on June 17, 2026, and immediately g [truncated]

HIGH BdThemes CVE published 2026-06-17

CVE-2026-40721

CVE-2026-40721 is a HIGH severity vulnerability (CVSS Score: 7.5) in Element Pack Pro plugin versions <= 9.0.6. This vulnerability allows for local file inclusion attacks, potentially enabling attackers to access sensitive files on the server. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of Element Pack Pro should update to a patched version to mitigate this risk.

MEDIUM bdthemes CVE published 2026-04-08

CVE-2026-4655

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. Authenticated attackers with Contributor-level access and above may inject arbitrary JavaScript in SVG [truncated]

MEDIUM bdthemes CVE published 2026-04-08

CVE-2026-4341

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget se [truncated]