bdthemes Vulnerabilities and Affected Products
Vulnerabilities associated with Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor.
Products
Clear product- Element Pack – Widgets, Templates & Addons for Elementor29 vulnerabilities
- Prime Slider – Addons for Elementor17 vulnerabilities
- Ultimate Store Kit Elementor Addons12 vulnerabilities
- Element Pack Elementor Addons9 vulnerabilities
- Element Pack Pro4 vulnerabilities
- prime_slider4 vulnerabilities
- ZoloBlocks4 vulnerabilities
- Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor3 vulnerabilities
- Instant Image Generator2 vulnerabilities
- Ultimate Post Kit Addons for Elementor2 vulnerabilities
- utlimate_store_kit_elementor_addons2 vulnerabilities
- ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns2 vulnerabilities
- Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons1 vulnerability
- Element Pack Elementor Addons and Templates1 vulnerability
- Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin1 vulnerability
- element_pack_elementor_addons1 vulnerability
- instant_image_generator1 vulnerability
- Live Copy Paste for Elementor1 vulnerability
- Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery1 vulnerability
- SigmaForms Pro – AI Generated Forms1 vulnerability
- Spin Wheel – Interactive spinning wheel that offers coupons1 vulnerability
- Ultimate Post Kit1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-2168MEDIUM | Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.4.1 - Cross-Site Request Forgery to Limited User Meta UpdateThe Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated attackers to set arbitrary user meta values to `1` which can be leveraged to lock and administrator out of their site v… CWE-352May 1, 2025 | CVSS4.3v3.1 | EPSS0.191% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8030CRITICAL | Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object InjectionThe Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or… CWE-502Aug 28, 2024 | CVSS9.8v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5335CRITICAL | Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object InjectionThe Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products cookie in versions up to , and including, 1.6.4. This makes it possible for an unauthenticated attacker to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additiona… CWE-502Aug 21, 2024 | CVSS9.8v3.1 | EPSS0.852% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |