← WordPress Vulnerabilities
WordPress security by component

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider)

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jan 23, 2025; the highest CVE/CNA score is 6.4.

Plugin slug: prime-slider

CVE-2024-12043: Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider): Cross-site scripting

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJan 23, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 23, 2025 CVE-2024-12043
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider): Cross-site scripting
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 23, 2024 CVE-2024-3997
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider): Cross-site scripting
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-4339
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider): Cross-site scripting
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 20, 2024 CVE-2024-1730
Prime Slider: Cross-site scripting
Prime Slider is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 13, 2024 CVE-2024-1508
Prime Slider – Addons For Elementor: Cross-site scripting
Prime Slider – Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1507
Prime Slider – Addons For Elementor: Cross-site scripting
Prime Slider – Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 07, 2024 CVE-2024-1506
Prime Slider – Addons For Elementor: Cross-site scripting
Prime Slider – Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4