CVE-2026-92991: Bdthemes Element Pack Addons For Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected products
- Bdthemes Element Pack Addons For Elementor – Elementor Widgets, Elementor Templates, Elementor Addons: up to and including 8.7.14
- Bdthemes Live Copy Paste For Elementor – Cross Domain Copy Paste & Page Duplicator: up to and including 1.5.6
- Bdthemes Pixel Gallery Addons For Elementor: up to and including 2.1.14
- Bdthemes Prime Slider – Hero Slider, Carousel, Woocommerce & Post Slider Elementor Addons: up to and including 4.4.5
- Bdthemes Smart Admin Assistant: up to and including 2.2.0
- Bdthemes Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets: up to and including 4.2.0
- Bdthemes Ultimate Store Kit – Store Builder Addons For Elementor, Woocommerce Store Builder, Edd Store Builder: up to and including 3.0.7
Published 2026-09-18. Last modified 2026-09-18.