bdthemes Vulnerabilities and Affected Products
Vulnerabilities associated with Spin Wheel – Interactive spinning wheel that offers coupons.
Products
Clear product- Element Pack – Widgets, Templates & Addons for Elementor29 vulnerabilities
- Prime Slider – Addons for Elementor17 vulnerabilities
- Ultimate Store Kit Elementor Addons12 vulnerabilities
- Element Pack Elementor Addons9 vulnerabilities
- Element Pack Pro4 vulnerabilities
- prime_slider4 vulnerabilities
- ZoloBlocks4 vulnerabilities
- Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor3 vulnerabilities
- Instant Image Generator2 vulnerabilities
- Ultimate Post Kit Addons for Elementor2 vulnerabilities
- utlimate_store_kit_elementor_addons2 vulnerabilities
- ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns2 vulnerabilities
- Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons1 vulnerability
- Element Pack Elementor Addons and Templates1 vulnerability
- Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin1 vulnerability
- element_pack_elementor_addons1 vulnerability
- instant_image_generator1 vulnerability
- Live Copy Paste for Elementor1 vulnerability
- Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery1 vulnerability
- SigmaForms Pro – AI Generated Forms1 vulnerability
- Spin Wheel – Interactive spinning wheel that offers coupons1 vulnerability
- Ultimate Post Kit1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-0808MEDIUM | Spin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' ParameterThe Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for unauthenticated attackers to manipulate which prize they win by modifying the 'prize_index' parameter sent to the server, allowing them to always select the most valuable prizes. CWE-602Jan 17, 2026 | CVSS5.3v3.1 | EPSS0.312% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |