Find notable cyber news and cases, enriched with sources, timelines, and signals.

Prime Slider unescaped HTML attribute security flaw

Vulnerability
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-admin page loads. The issue was introduced on March 1 and was still unpatched at publication.

Related Happenings

BdThemes hit by network compromise

Incident
H score22 First: 10.08.2026 17:30 Last: 10.08.2026 17:30 Sources 1

How related: Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified.

About this happening: A BdThemes WordPress plugin supply-chain compromise planted rogue administrator accounts and webshells on live sites, risking full site control. The malicious payload...

Timeline

  1. 10.08.2026 17:30 2 articles · 2h ago

    Prime Slider script concatenates an unescaped remote JSON field into an HTML attribute

    Technical Analysis Update

    BdThemes adds a Prime Slider script that takes a field from the remote JSON response and concatenates it directly into an HTML attribute without escaping it, creating a browser-side code execution path that can fire on every wp-admin page load for a logged-in administrator.

    Show sources
  2. 08.08.2026 03:00 1 articles · 2d ago

    Wordfence publishes analysis of the Prime Slider HTML attribute flaw

    Initial Disclosure

    Wordfence says it was notified on August 7, published its analysis on August 8, and rates the Prime Slider issue 5.4/medium severity as unpatched; BdThemes' seven WordPress.org plugins were temporarily closed pending review.

    Show sources