Prime Slider unescaped HTML attribute security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-admin page loads. The issue was introduced on March 1 and was still unpatched at publication.
Related Happenings
BdThemes hit by network compromise
Incident
H score22
First: 10.08.2026 17:30
Last: 10.08.2026 17:30
Sources 1
How related:
Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified.
About this happening:
A BdThemes WordPress plugin supply-chain compromise planted rogue administrator accounts and webshells on live sites, risking full site control. The malicious payload...
BdThemes hit by network compromise
IncidentHow related: Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified.
About this happening: A BdThemes WordPress plugin supply-chain compromise planted rogue administrator accounts and webshells on live sites, risking full site control. The malicious payload...
Timeline
-
10.08.2026 17:30 2 articles · 2h ago
Prime Slider script concatenates an unescaped remote JSON field into an HTML attribute
Technical Analysis UpdateBdThemes adds a Prime Slider script that takes a field from the remote JSON response and concatenates it directly into an HTML attribute without escaping it, creating a browser-side code execution path that can fire on every wp-admin page load for a logged-in administrator.
Show sources
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30
-
08.08.2026 03:00 1 articles · 2d ago
Wordfence publishes analysis of the Prime Slider HTML attribute flaw
Initial DisclosureWordfence says it was notified on August 7, published its analysis on August 8, and rates the Prime Slider issue 5.4/medium severity as unpatched; BdThemes' seven WordPress.org plugins were temporarily closed pending review.
Show sources
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30